XCSSET v40: The New Threat to macOS and Developers

After months of inactivity, the attackers behind the XCSSET malware have released version 40 (v40), specifically targeting the macOS ecosystem. This version features an advanced architecture that hides its main logic in memory space, thus reducing its digital footprint.

New Evasion and Spread Techniques

Version v40 further enhances its detection evasion capabilities by combining polymorphic payload generation with fileless persistence and dynamic in-memory execution. Additionally, it weakens several security mechanisms on infected machines. Since the beginning of April 2026, the malware has spread through supply chain attacks, hiding in Xcode projects of dozens of legitimate applications with thousands of active users. Xcode is Apple's integrated development environment (IDE) for creating apps for its various operating systems. The authors of XCSSET have enhanced the malware's ability to spread through open-source projects on GitHub and have updated its worm capabilities, allowing it to infect all existing Xcode projects on a compromised system for maximum impact.

Advanced Hiding Techniques

The malware authors used a multi-level scroll cipher to hide the threat's internal functions. In response, researchers leveraged advanced artificial intelligence algorithms and pattern matching to de-obfuscate the malware's logic.

XCSSET v40 Infection Chain

The XCSSET v40 infection chain consists of four distinct phases before the final payload execution: 1. Initial Script: Establishes communication with the command and control (C2) server. 2. Second Phase: Collects basic system fingerprinting information and downloads additional modules. 3. Third Phase: Includes a temporary staging applet that is deposited on the system to load the final phase into volatile memory space. 4. Fourth Phase: This is the main module logic. As soon as this main module loop residing in memory becomes active, the malware terminates its staging processes and deletes all installation files from the disk. The main module's (internally called boot) goal is to execute and load further specialized modules in memory, such as keyloggers, clipboard hijackers, or browser hijackers.

XCSSET v40 Modules

Our analysis of XCSSET v40 revealed 17 distinct modules, each designed for a different purpose. The modules were delivered via a dynamic C2 infrastructure and executed in memory. We found that the operators improved several of its legacy modules while introducing two new ones. These include a backdoor for Chrome hijacking and a Telegram trojanizer.

Chrome Hijacking Module

The Chrome hijacking module controls the browser by exploiting a legitimate Chromium function, the CDP (Chrome DevTools Protocol). For CDP-based hijacking, the malware must redirect how the user interacts with the browser. It does this by wrapping it in a malicious persistence script. When a victim launches Google Chrome, the wrapper executes a three-step chain: 1. Orchestrator Verification: Restarts the main XCSSET orchestrator module (boot) every time Google Chrome is initialized, ensuring the malware's main process remains active. 2. CDP Execution: Then launches the legitimate Google Chrome application with specific command-line arguments that activate the CDP on a predefined local port, exposing the browser's internal engine. 3. Chromeremote Backdoor: Finally, deposits and launches a specialized Chrome hijacking binary (chromeremote). This binary connects to the open CDP port, allowing attackers to execute arbitrary JavaScript, manipulate active browser sessions, and extract cookie tokens invisibly.

Telegram Trojanizer Module

We identified a new Telegram Desktop trojanizer module in May 2026, absent in the April 2026 distribution. This module performs the following activities:
  • Downloads a pre-built malicious Telegram.app ZIP archive.
  • Canc
  • Mitigation and Protection

    To protect against this threat, it is essential to adopt the following mitigation strategies:
  • Regular Updates: Keep the operating system and applications up to date, particularly Xcode and Google Chrome.
  • Advanced Monitoring: Implement advanced security solutions that use artificial intelligence algorithms and pattern matching to detect and prevent such threats.
  • Secure Development Practices: Developers should adopt secure development practices, such as code review and the use of secure repositories for open-source projects.
  • If you suspect you have been compromised or have an urgent issue, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html). The v40 version of XCSSET represents a significant threat to macOS developers, thanks to its advanced evasion and spread techniques. Understanding the infection chain and modules of this new version is crucial for developing effective mitigation strategies and protecting systems from attacks.

    Impact and Emerging Trends

    The spread of XCSSET v40 has shown a significant concentration of attacks against developers in South Asia, in line with patterns observed since the malware's initial discovery in 2020. This geographic shift suggests a possible strategic adaptation by the attackers, who may be exploiting regional differences in security practices or threat awareness. The increase in attacks in this region could also indicate greater vulnerability of local open-source projects or development infrastructures, making them easier targets for aggressors.

    Evolution of the Infection Chain

    One of the most concerning aspects of XCSSET v40 is its evolution of the infection chain. This version of the malware has developed sophisticated techniques to evade detection and spread more effectively. For instance, it uses polymorphic payloads that change their appearance to avoid signature-based detection. Additionally, it employs fileless persistence methods, making it harder to detect and remove. These advancements make XCSSET v40 a formidable threat in the current threat landscape.

    Advanced Mitigation Strategies

    To protect against XCSSET v40 and its future evolutions, it is essential to adopt a combination of advanced mitigation strategies. Here are some additional recommendations:
  • Behavioral Analysis: Implement security solutions that use behavioral analysis to detect suspicious activities, such as the execution of malicious scripts or the manipulation of legitimate applications.
  • File Modification Control: Carefully monitor file modifications in Xcode projects and Git repositories, particularly those that may have been compromised by supply chain attacks.
  • Isolation of Critical Applications: Run critical applications like Google Chrome and Telegram in isolated or sandboxed environments, limiting their access to system resources and reducing potential damage in case of infection.
  • Developer Training: Provide continuous training to developers on best security practices, including recognizing signs of malware infection and the importance of keeping their development tools up to date.
  • XCSSET v40 represents a sophisticated and evolved threat to macOS developers, with advanced evasion and spread capabilities. Its ability to hide its core code in memory, combined with the use of polymorphic payloads and malicious modules, makes it one of the most dangerous threats in the current landscape. To counter this threat, it is crucial to adopt a proactive approach to security, using advanced technologies and robust mitigation practices. Only through a combination of vigilance, innovation, and collaboration can the security community effectively protect systems from XCSSET v40 attacks and its future variants.

    Editorial Note and Disclaimer

    The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

    GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

    The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the misuse of the information published.

    In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.