Back to feed
Dev.to
Dev.to
8/1/2026
XCSSET v40: From Xcode Supply Chain to Memory-Resident and Browser/Telegram Hijacking

XCSSET v40: From Xcode Supply Chain to Memory-Resident and Browser/Telegram Hijacking

Short summary

Unit 42 details XCSSET v40, a macOS supply chain malware that injects malicious run-scripts into legitimate Xcode projects on GitHub. After C2 approval, it executes 17 in-memory modules to hijack Chrome sessions via DevTools Protocol and replace Telegram with a trojanized version. The malware self-replicates into other local Xcode projects, spreading to additional developers and build artifacts.

  • XCSSET v40 injects malicious scripts into Xcode projects from GitHub
  • 17 in-memory modules steal Chrome cookies and replace Telegram with trojanized app
  • Self-replicates across local Xcode projects to spread to other developers

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more