XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
ID: 877e44e1-acc2-51bf-8f72-e9f2dbfb292f
STIX ID: report--877e44e1-acc2-51bf-8f72-e9f2dbfb292f
Feed Name: GBHackers
XCSSET v40 is a highly evasive macOS supply-chain campaign that compromises Xcode projects and GitHub-hosted repos to infect developer workstations; it runs primarily in memory, uses polymorphic and per-build encryption, and dynamically loads modules for Chrome hijacking (via the Chrome DevTools Protocol), Telegram trojanizing, keylogging, clipboard theft and data exfiltration. The report details a four-phase execution pipeline, dual-key network encryption, anti-VM and macOS security sabotage, rotating C2 infrastructure with multiple domains/paths, and provides actionable IOCs for detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
