XCSSET v40 Locks macOS Out of Its Own Security Updates

Amber | Attack
Download PDF
TA2026223 | XCSSET v40: Modular macOS Malware Blocks XProtect and Hijacks Xcode Projects

XCSSET hides a downloader script in Xcode projects and Git repositories, infecting hosts only when a developer builds the poisoned project. XCSSET v40, active since mid-April 2026, infects every other Xcode project it reaches, turning developer workstations into supply chain vectors.


The XCSSET v40 Infection Chain

1

Self-propagating supply-chain infection

XCSSET injects a downloader script into Xcode/Git projects, infecting hosts only on build; v40 hid in dozens of legitimate apps and infects every other Xcode project it reaches.

2

Dormant until build, then silent C2 contact

A poisoned codebase stays dormant until built, then a run-script build phase silently contacts the attacker’s server for the next stage.

3

Four-stage, memory-resident execution

Execution runs in four memory-resident stages: metadata staging, hardware fingerprinting, an osascript-run AppleScript wrapper, and an orchestrator decrypting keyloggers in memory.

4

Fingerprint rotation, defense evasion

V40 recompiles its loader hourly under per-build keys, persists via Git hooks and Launch Daemons, and blocks XProtect/MRT/TCC updates while posing as System Settings.

5

Reused infrastructure fingerprints

Exfiltration uses separate C2 endpoints for logs, uploads, and browser-hijack events, with ~40 domains reused across campaigns sharing one SSL thumbprint.


Containing an XCSSET v40 Infection

1

Scan every Xcode project

XCSSET infects every Xcode project on a host, including those inside .zip archives, so one confirmed infection requires a full home-directory sweep.

2

Inspect Git hooks and shell startup files

Check hooks/pre-commit and ~/.zshrc for appended payload lines, which survive removal and re-infect on the next commit.

3

Monitor osascript execution

Deploy behavioral detection for abnormal osascript from Xcode build phases; v40 runs in memory and deletes staging files immediately, so telemetry is often the only evidence.

4

Block untrusted local binaries

Track ad hoc code-signed applications and isolate binaries that bypass Gatekeeper; XCSSET signs fake Launchpad, Finder, and Xcode bundles plus a trojanized Telegram app.

5

Rotate credentials and SSH keys

Treat browser cookies, cloud/Apple ID credentials, and crypto wallet material on affected hosts as compromised, and audit ~/.ssh for rogue keys.


MITRE ATT&CK TTPs

T1583 / T1583.001
Resource Development
Acquire Infrastructure — Domains
T1195 / T1195.001
Initial Access
Supply Chain Compromise — Compromise Software Dependencies and Development Tools
T1059 / T1059.002, T1059.004, T1059.007
Execution
Command and Scripting Interpreter — AppleScript, Unix Shell, JavaScript
T1569 / T1569.001
Execution
System Services — Launchctl
T1546 / T1546.004
Persistence
Event Triggered Execution — Unix Shell Configuration Modification
T1543 / T1543.004
Persistence
Create or Modify System Process — Launch Daemon
T1647
Persistence
Plist File Modification
T1554
Persistence
Compromise Host Software Binary
T1098 / T1098.004
Persistence
Account Manipulation — SSH Authorized Keys
T1068
Privilege Escalation
Exploitation for Privilege Escalation
T1548 / T1548.006
Privilege Escalation
Abuse Elevation Control Mechanism — TCC Manipulation
T1562 / T1562.001, T1562.004
Defense Evasion
Impair Defenses — Disable or Modify Tools, Disable or Modify System Firewall
T1027 / T1027.013, T1027.004
Defense Evasion
Obfuscated Files or Information — Encrypted/Encoded File, Compile After Delivery
T1140
Defense Evasion
Deobfuscate/Decode Files or Information
T1036 / T1036.005
Defense Evasion
Masquerading — Match Legitimate Name or Location
T1553 / T1553.001
Defense Evasion
Subvert Trust Controls — Gatekeeper Bypass
T1070 / T1070.004
Defense Evasion
Indicator Removal — File Deletion
T1574 / T1574.006
Defense Evasion
Hijack Execution Flow — Dynamic Linker Hijacking
T1564 / T1564.001, T1564.003
Defense Evasion
Hide Artifacts — Hidden Files and Directories, Hidden Window
T1222 / T1222.002
Defense Evasion
File and Directory Permissions Modification — Linux and Mac File and Directory Permissions Modification
T1497 / T1497.003
Defense Evasion
Virtualization/Sandbox Evasion — Time Based Checks
T1539
Credential Access
Steal Web Session Cookie
T1555 / T1555.003
Credential Access
Credentials from Password Stores — Credentials from Web Browsers
T1056 / T1056.001, T1056.002
Credential Access
Input Capture — Keylogging, GUI Input Capture
T1185
Credential Access
Browser Session Hijacking
T1082
Discovery
System Information Discovery
T1033
Discovery
System Owner/User Discovery
T1083
Discovery
File and Directory Discovery
T1518 / T1518.001
Discovery
Software Discovery — Security Software Discovery
T1217
Discovery
Browser Information Discovery
T1087
Discovery
Account Discovery
T1614 / T1614.001
Discovery
System Location Discovery — System Language Discovery
T1005
Collection
Data from Local System
T1115
Collection
Clipboard Data
T1113
Collection
Screen Capture
T1560
Collection
Archive Collected Data
T1071 / T1071.001
Command and Control
Application Layer Protocol — Web Protocols
T1573 / T1573.001
Command and Control
Encrypted Channel — Symmetric Cryptography
T1105
Command and Control
Ingress Tool Transfer
T1041
Exfiltration
Exfiltration Over C2 Channel
T1565 / T1565.002
Impact
Data Manipulation — Transmitted Data Manipulation
T1486
Impact
Data Encrypted for Impact

XCSSET v40 Indicators of Compromise

TypeValue
SHA2566fa938770e83ef2e177e8adf4a2ea3d2d5b26107c30f9d85c3d1a557db2aed417e5343362fceeae3f44c7ca640571a1b148364c4ba296ab6f8d264fc2c62cb61857dc86528d0ec8f5938680e6f89d846541a41d62f71d003b74b0c55d645cda76614978ab256f922d7b6dbd7cc15c6136819f4bcfb5a0fead480561f0df54ca6ac3467a04eeb552d92651af1187bdc795100ea77a7a1ac755b4681c654b54692d11a549e6bc913c78673f4e142e577f372311404766be8a3153792de9f00f6c1532837d19b6446a64cb8b199c9406fd46aa94c3fe41111a373426b9ce59f56f94f78afd616bfefaa780771e69a71915e67ee6dbcdc1bc98587e219e120f3ea0d819ba3c3ef77d00eae1afa8d2db055813190c3d133de2c2c837699a0988d649373f203b5e37cf34e51f7bf457b0db8e4d2524f81e41102da7a26f5590ab32cd9ccc2e6de03c0f3315b9e8e05967fcc791d063a392277f063980d3a1b39db20796622887a849b503b120cfef8cd76cd2631a5d0978116444a9cb92b1493e42c2932fa0cdb46f204fc370c86c3e93fa01e5f5cb5a460407333c24dc79953206443924a89866ea55ee932dabb304f851187d97806ab60865a04ccd91a0d1b992246af3a2c0d14cc51cc8615da4d99f33110f95b7091111d20bdba40c91ef759b4d7534f453238cfc4bb13fda70ed2cda701f3fb52b5d81de9d8d00da74bc97ec7f6172eb05a2f72cb89e38be3ac91fd13929ee536073d1fe576bc8b8d8d6ec6c262a238ed8a801e48300169afae7d27b5e49a946661ed91fab4f792e99243fbc28dd338dc9a75a14753f57399815b5d996a1c5e65aa4eb203222d8c85fb3d74b02f56670f51f94080f1ae45f2a433767f210f290835bf582e1a2e1876f1028832def67e2a27f0d1a4667b065ab05f884ff881eb7627e9d458f97f2204647b339c6e25d226d5cb0c74ed5b1b85f12d53a4c2de2147ff464b2a35db03987015b11e24c2a7970216576a6b8f74528ffcfa51aa2b72b7f3e4237d97715b1b5ba80b25ca8cec3c106659709017bb253becf68296c7bf13e76fa92b4450c281003d225645ea90c72e67f1c9a9231732119576a7dcb29471f7da428866187d4326e78097f2ff83f53a383ba3f1d6b002006adf16a7f0b3263185d56cb70104889874d67c5dcc37a01d3351b3c166f04aec6f52849e909b0b9c8d55095d730c660691b1ba66
Domainsaccapple[.]ruadschecks[.]ruadsmobi[.]ruadsmorein[.]inadsmoreme[.]inamdcdn[.]ruamzndev[.]inamzndev[.]ruamznprod[.]inapplecdn[.]ruappledisk[.]ruappledns[.]ruapplehosts[.]ruappletime[.]inbulksec[.]rucdnamz[.]incdnamz[.]rucdnapple[.]incdnatapple[.]rucdnroute[.]rucheckcdn[.]ruchromeads[.]rucnmag[.]rudevnetaps[.]rudnsapple[.]rudnsrelays[.]ruexplorecdn[.]rufiddlejoy[.]rufigmacat[.]rufigmanets[.]infunchats[.]rugironetcdn[.]rugoalmate[.]rugooglenets[.]rugreencn[.]ruicloudsnet[.]ruimails[.]rulegalads[.]inlittleads[.]inlittledns[.]rumaganet[.]rumindelgate[.]runetapsdev[.]runetcdnads[.]innetcdnamz[.]runetcdndev[.]innetcorps[.]runetsprot[.]innetsproto[.]innetworkads[.]inrigacdn[.]inrigmajoys[.]inrigmanet[.]rurigmanets[.]insahusuzuki[.]instuffdns[.]intestjoys[.]rutimewebnet[.]invigmanet[.]ruwhitead[.]inwhiteads[.]ruwincdn[.]ruwindsecure[.]rubulknames[.]rucastlenet[.]ruchaoping[.]rudevapple[.]rugigacells[.]rugizmodoc[.]rutrixmate[.]ruitoyads[.]rurigglejoy[.]rurutornet[.]rusigmate[.]ruvivatads[.]rufigmasol[.]ruadobestats[.]comflixprice[.]com
URLshxxps[:]//amzndev[.]in/d/zw_sfp64hxxps[:]//amzndev[.]ru/d/zw_sfp64hxxps[:]//googlenets[.]ru/d/zw_sfp64hxxps[:]//netcdndev[.]in/d/zw_sfp64hxxps[:]//whitead[.]in/d/zw_sfp64hxxps[:]//whiteads[.]ru/d/zw_sfp64hxxps[:]//bulknames[.]ru/a
IPv491[.]108[.]106[.]22995[.]142[.]35[.]3495[.]142[.]35[.]20695[.]142[.]37[.]159151[.]243[.]109[.]188178[.]208[.]92[.]129178[.]208[.]92[.]16846[.]101[.]126[.]33
Filenamesmain.scptxcassetsAssets.xcassetsPodsPods_shadproject.xworkspacebuild.shspeeddfirefoxdoperadyandexdedgedbravedagentdagentdkillagentdlogdskwalpchkdskzw_sfp64chrome_remoteloozsafari.ziprun-safari-dev.pySafari131Mojave.pkgSafari1304Mojave.pkg7zadockutilbase_tr_file.txtbase_tr_map.txtInfoPlist.locatable
File Path/tmp/r/tmp/p.app/tmp/b/tmp/l.app/tmp/.n/tmp/.f/tmp/.i/tmp/.e/tmp/out.txt~/.tr~/.tr_map~/.a~/.zshrc~/.zshrc_aliases~/Library/Caches/GameKit/~/Library/Caches/com.apple.finder~/Library/Frameworks.app~/Library/CoreFramework~/Library/LaunchAgents/com.apple.core.launchd.plist~/Library/LaunchAgents/com.apple.core.accountsd.plist~/Library/Cookies/Cookies.binarycookies/Library/Application Support/com.apple.frameworks/Applications/SimulatorTrampoline.app/Applications/Reminders.app/Applications/Reminders.app/Notes//Applications/Terminal.app/Applications/Finder.app/Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment
SSL Certificate Thumbprint6e480d648fa1b70612f5d198a66875e28847547d

References

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.