Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
XCSSET v40 Targets macOS Devs via Compromised Xcode

XCSSET v40 Targets macOS Devs via Compromised Xcode

Posted on August 3, 2026 By CWS

XCSSET v40 malware has emerged as a significant threat to macOS developers, utilizing compromised Xcode projects to infiltrate and execute a supply chain attack. The malware’s latest version spreads through these infected projects, posing a risk to developers and organizations that rely on their software.

XCSSET’s Stealthy Evolution

Originally identified in 2020, XCSSET has continually evolved, focusing on stealth and scalability. The malware uses memory-based execution and rapidly changing payloads to minimize detection. Recent reports indicate an increased focus on developers in South Asia, with infected projects surfacing in open-source repositories.

Unit 42 analysts detected the v40 activity in April 2026, noting a resurgence in May with additional components. According to Palo Alto Networks, XCSSET has been embedded into numerous Xcode projects linked to active applications, highlighting the potential scale of the threat.

Exploiting Chrome DevTools Protocol

XCSSET v40 introduces a backdoor that exploits the Chrome DevTools Protocol (CDP), a legitimate browser automation feature. By wrapping the genuine Chrome app in a malicious launcher, it reactivates XCSSET each time Chrome is opened, enabling CDP on a local port.

This mechanism allows the malware to run scripts within active browser sessions, steal cookie tokens, and monitor web traffic. The use of a trusted browser functionality, rather than a flaw, underscores the significance of recent Chrome DevTools security updates.

Mitigation Strategies for Developers

Developers must scrutinize project settings and source code to detect hidden scripts that could trigger further attacks. XCSSET’s ability to execute remote commands via Chrome makes traditional file-based security checks insufficient.

Unit 42 recommends vigilance for unusual AppleScript activity, unauthorized browser launches, and irregular preference domains. Isolating ad hoc-signed binaries, scanning dependencies, and inspecting Xcode projects for unfamiliar scripts are crucial steps in mitigating this threat.

Conclusion: Strengthening Security Measures

The XCSSET v40 campaign highlights the vulnerabilities inherent in trusted development tools. Organizations are urged to monitor behavior across repositories and network connections, verify project origins, and update security protocols to mitigate such threats.

Ultimately, safeguarding against XCSSET v40 requires an understanding of its techniques and a commitment to maintaining robust security practices across development environments and tools.

Cyber Security News Tags:browser security, Chrome DevTools, cyber threat, Cybersecurity, macOS, Malware, software developers, supply chain attack, Xcode, XCSSET

Post navigation

Previous Post: Cyberattacks on US Water Systems Linked to Iran
Next Post: Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks

Related Posts

Microsoft 365 Copilot Security Issue Risks Email Privacy Microsoft 365 Copilot Security Issue Risks Email Privacy Cyber Security News
Threat Actors Claim Breach Of Huawei Technologies Source Code and Internal Tools Threat Actors Claim Breach Of Huawei Technologies Source Code and Internal Tools Cyber Security News
Automatic BitLocker Encryption May Silently Lock Away Your Data Automatic BitLocker Encryption May Silently Lock Away Your Data Cyber Security News
What Businesses Need to Know What Businesses Need to Know Cyber Security News
Rising Cyber Threats Challenge Defense Sector Security Rising Cyber Threats Challenge Defense Sector Security Cyber Security News
Preventing Phishing Attacks on Cryptocurrency Exchanges Preventing Phishing Attacks on Cryptocurrency Exchanges Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI’s Role in Modern Security Operations Explained
  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks
  • XCSSET v40 Targets macOS Devs via Compromised Xcode

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI’s Role in Modern Security Operations Explained
  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks
  • XCSSET v40 Targets macOS Devs via Compromised Xcode

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark