logo

Microsoft: New Variant of macOS Threat XCSSET Spotted in the Wild

ID: c998b578-9f5f-5e7e-b59e-3ea6e16a6a20

STIX ID: report--c998b578-9f5f-5e7e-b59e-3ea6e16a6a20

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-02-18

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

Microsoft published analysis of an updated XCSSET macOS malware variant targeting Xcode developers: the variant adds stronger obfuscation, new persistence mechanisms (a ~/.zshrc_aliases method and a dock/Launchpad hijack via a signed dockutil), and multiple infection strategies that enable wormable supply-chain spread; it can exfiltrate data from Safari and apps (Skype, Telegram, WeChat, Notes), take screenshots, target digital wallets, and encrypt files, and defenders are advised to inspect downloaded Xcode projects and use Microsoft Defender for Endpoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.