
Summary
XCSSET hides a downloader script in Xcode projects and Git repositories, infecting hosts only when a developer builds the poisoned project. XCSSET v40, active since mid-April 2026, infects every other Xcode project it reaches, turning developer workstations into supply chain vectors.
Attack Details
Self-propagating supply-chain infection
XCSSET injects a downloader script into Xcode/Git projects, infecting hosts only on build; v40 hid in dozens of legitimate apps and infects every other Xcode project it reaches.
Dormant until build, then silent C2 contact
A poisoned codebase stays dormant until built, then a run-script build phase silently contacts the attacker’s server for the next stage.
Four-stage, memory-resident execution
Execution runs in four memory-resident stages: metadata staging, hardware fingerprinting, an osascript-run AppleScript wrapper, and an orchestrator decrypting keyloggers in memory.
Fingerprint rotation, defense evasion
V40 recompiles its loader hourly under per-build keys, persists via Git hooks and Launch Daemons, and blocks XProtect/MRT/TCC updates while posing as System Settings.
Reused infrastructure fingerprints
Exfiltration uses separate C2 endpoints for logs, uploads, and browser-hijack events, with ~40 domains reused across campaigns sharing one SSL thumbprint.
Recommendations
Scan every Xcode project
XCSSET infects every Xcode project on a host, including those inside .zip archives, so one confirmed infection requires a full home-directory sweep.
Inspect Git hooks and shell startup files
Check hooks/pre-commit and ~/.zshrc for appended payload lines, which survive removal and re-infect on the next commit.
Monitor osascript execution
Deploy behavioral detection for abnormal osascript from Xcode build phases; v40 runs in memory and deletes staging files immediately, so telemetry is often the only evidence.
Block untrusted local binaries
Track ad hoc code-signed applications and isolate binaries that bypass Gatekeeper; XCSSET signs fake Launchpad, Finder, and Xcode bundles plus a trojanized Telegram app.
Rotate credentials and SSH keys
Treat browser cookies, cloud/Apple ID credentials, and crypto wallet material on affected hosts as compromised, and audit ~/.ssh for rogue keys.
MITRE ATT&CK TTPs
Indicators of Compromise (IoCs)
| Type | Value |
|---|---|
| SHA256 | 6fa938770e83ef2e177e8adf4a2ea3d2d5b26107c30f9d85c3d1a557db2aed417e5343362fceeae3f44c7ca640571a1b148364c4ba296ab6f8d264fc2c62cb61857dc86528d0ec8f5938680e6f89d846541a41d62f71d003b74b0c55d645cda76614978ab256f922d7b6dbd7cc15c6136819f4bcfb5a0fead480561f0df54ca6ac3467a04eeb552d92651af1187bdc795100ea77a7a1ac755b4681c654b54692d11a549e6bc913c78673f4e142e577f372311404766be8a3153792de9f00f6c1532837d19b6446a64cb8b199c9406fd46aa94c3fe41111a373426b9ce59f56f94f78afd616bfefaa780771e69a71915e67ee6dbcdc1bc98587e219e120f3ea0d819ba3c3ef77d00eae1afa8d2db055813190c3d133de2c2c837699a0988d649373f203b5e37cf34e51f7bf457b0db8e4d2524f81e41102da7a26f5590ab32cd9ccc2e6de03c0f3315b9e8e05967fcc791d063a392277f063980d3a1b39db20796622887a849b503b120cfef8cd76cd2631a5d0978116444a9cb92b1493e42c2932fa0cdb46f204fc370c86c3e93fa01e5f5cb5a460407333c24dc79953206443924a89866ea55ee932dabb304f851187d97806ab60865a04ccd91a0d1b992246af3a2c0d14cc51cc8615da4d99f33110f95b7091111d20bdba40c91ef759b4d7534f453238cfc4bb13fda70ed2cda701f3fb52b5d81de9d8d00da74bc97ec7f6172eb05a2f72cb89e38be3ac91fd13929ee536073d1fe576bc8b8d8d6ec6c262a238ed8a801e48300169afae7d27b5e49a946661ed91fab4f792e99243fbc28dd338dc9a75a14753f57399815b5d996a1c5e65aa4eb203222d8c85fb3d74b02f56670f51f94080f1ae45f2a433767f210f290835bf582e1a2e1876f1028832def67e2a27f0d1a4667b065ab05f884ff881eb7627e9d458f97f2204647b339c6e25d226d5cb0c74ed5b1b85f12d53a4c2de2147ff464b2a35db03987015b11e24c2a7970216576a6b8f74528ffcfa51aa2b72b7f3e4237d97715b1b5ba80b25ca8cec3c106659709017bb253becf68296c7bf13e76fa92b4450c281003d225645ea90c72e67f1c9a9231732119576a7dcb29471f7da428866187d4326e78097f2ff83f53a383ba3f1d6b002006adf16a7f0b3263185d56cb70104889874d67c5dcc37a01d3351b3c166f04aec6f52849e909b0b9c8d55095d730c660691b1ba66 |
| Domains | accapple[.]ruadschecks[.]ruadsmobi[.]ruadsmorein[.]inadsmoreme[.]inamdcdn[.]ruamzndev[.]inamzndev[.]ruamznprod[.]inapplecdn[.]ruappledisk[.]ruappledns[.]ruapplehosts[.]ruappletime[.]inbulksec[.]rucdnamz[.]incdnamz[.]rucdnapple[.]incdnatapple[.]rucdnroute[.]rucheckcdn[.]ruchromeads[.]rucnmag[.]rudevnetaps[.]rudnsapple[.]rudnsrelays[.]ruexplorecdn[.]rufiddlejoy[.]rufigmacat[.]rufigmanets[.]infunchats[.]rugironetcdn[.]rugoalmate[.]rugooglenets[.]rugreencn[.]ruicloudsnet[.]ruimails[.]rulegalads[.]inlittleads[.]inlittledns[.]rumaganet[.]rumindelgate[.]runetapsdev[.]runetcdnads[.]innetcdnamz[.]runetcdndev[.]innetcorps[.]runetsprot[.]innetsproto[.]innetworkads[.]inrigacdn[.]inrigmajoys[.]inrigmanet[.]rurigmanets[.]insahusuzuki[.]instuffdns[.]intestjoys[.]rutimewebnet[.]invigmanet[.]ruwhitead[.]inwhiteads[.]ruwincdn[.]ruwindsecure[.]rubulknames[.]rucastlenet[.]ruchaoping[.]rudevapple[.]rugigacells[.]rugizmodoc[.]rutrixmate[.]ruitoyads[.]rurigglejoy[.]rurutornet[.]rusigmate[.]ruvivatads[.]rufigmasol[.]ruadobestats[.]comflixprice[.]com |
| URLs | hxxps[:]//amzndev[.]in/d/zw_sfp64hxxps[:]//amzndev[.]ru/d/zw_sfp64hxxps[:]//googlenets[.]ru/d/zw_sfp64hxxps[:]//netcdndev[.]in/d/zw_sfp64hxxps[:]//whitead[.]in/d/zw_sfp64hxxps[:]//whiteads[.]ru/d/zw_sfp64hxxps[:]//bulknames[.]ru/a |
| IPv4 | 91[.]108[.]106[.]22995[.]142[.]35[.]3495[.]142[.]35[.]20695[.]142[.]37[.]159151[.]243[.]109[.]188178[.]208[.]92[.]129178[.]208[.]92[.]16846[.]101[.]126[.]33 |
| Filenames | main.scptxcassetsAssets.xcassetsPodsPods_shadproject.xworkspacebuild.shspeeddfirefoxdoperadyandexdedgedbravedagentdagentdkillagentdlogdskwalpchkdskzw_sfp64chrome_remoteloozsafari.ziprun-safari-dev.pySafari131Mojave.pkgSafari1304Mojave.pkg7zadockutilbase_tr_file.txtbase_tr_map.txtInfoPlist.locatable |
| File Path | /tmp/r/tmp/p.app/tmp/b/tmp/l.app/tmp/.n/tmp/.f/tmp/.i/tmp/.e/tmp/out.txt~/.tr~/.tr_map~/.a~/.zshrc~/.zshrc_aliases~/Library/Caches/GameKit/~/Library/Caches/com.apple.finder~/Library/Frameworks.app~/Library/CoreFramework~/Library/LaunchAgents/com.apple.core.launchd.plist~/Library/LaunchAgents/com.apple.core.accountsd.plist~/Library/Cookies/Cookies.binarycookies/Library/Application Support/com.apple.frameworks/Applications/SimulatorTrampoline.app/Applications/Reminders.app/Applications/Reminders.app/Notes//Applications/Terminal.app/Applications/Finder.app/Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment |
| SSL Certificate Thumbprint | 6e480d648fa1b70612f5d198a66875e28847547d |
References & Patch Links
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.