XCSSET v40 Malware Hijacks Chrome and Telegram via Poisoned Xcode Projects
Security researchers at Palo Alto Networks Unit 42 published an analysis on July 31, 2026, of XCSSET v40, a high-severity macOS malware targeting software developers. The malware spreads through poisoned Xcode projects hosted on platforms like GitHub, activating when a developer builds the project locally. Once a command-and-control server approves the target, a multi-stage loader executes 17 modules entirely in memory to steal browser data, log keystrokes, and hijack clipboard content. The malware wraps Google Chrome in a malicious launcher to enable session hijacking via Chrome DevTools Protocol, while also replacing the legitimate Telegram app with a trojanized version signed with an ad-hoc certificate. It further self-replicates into other Xcode projects on the infected machine, allowing it to spread to additional developers through shared code repositories.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in