logo

Microsoft spots XCSSET macOS malware variant used for crypto theft

ID: b049e433-92b6-502e-acec-977900e1c85a

STIX ID: report--b049e433-92b6-502e-acec-977900e1c85a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-02-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft warns of a new XCSSET macOS malware variant observed in limited attacks that steals digital wallets, Notes app data, credentials and other sensitive information by infecting Xcode projects; this variant adds stronger code obfuscation, new persistence techniques (~/.zshrc_aliases and a dock-based Launchpad hijack using a signed dockutil), and novel payload placement in Xcode build settings, increasing supply-chain risk for developers. Microsoft recommends inspecting and verifying Xcode projects and codebases from unofficial repositories to mitigate infection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.