CuraSec

Act active

New XCSSET variant targets macOS devs via compromised Xcode projects

2026-08-05 13:01 UTC · BleepingComputer · read the source ↗ #macos#supply-chain#malware
  • Engineer — Act: If your team uses Xcode or pulls macOS Swift/ObjC projects from GitHub, audit your local Xcode project files and CI runners for XCSSET indicators; verify integrity of any third-party Xcode project dependencies before building.
  • SOC/IR — Plan: Build or tune detections for XCSSET staging behaviors on macOS endpoints (e.g., suspicious Xcode project modifications, unexpected LaunchAgent/LaunchDaemon persistence); review EDR coverage for macOS developer machines.
  • Leader — Learn: Supply-chain compromise via developer tooling is a recurring risk pattern worth noting for future policy on approved Xcode project sources and macOS developer workstation standards.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.