XCSSET is a modular macOS backdoor and information-stealing malware family targeting Apple software developers through compromised Xcode projects and associated source-code repositories. Malicious build rules, scripts, and version-control hooks execute when a poisoned project is built, infecting the developer workstation and propagating into other local Xcode and development projects, creating a downstream software-supply-chain risk. XCSSET has also been observed embedded in a compromised Flutter package example project; dependency use alone did not execute the malicious code.
The malware performs host reconnaissance, including operating-system, user, hardware, locale, firewall, System Integrity Protection, virtual-machine, and security-control checks. It uses hidden artifacts, obfuscated and polymorphic payloads, in-memory execution, short-lived staging components, encrypted command-and-control communications, and repeated loader recompilation to evade detection. Persistence mechanisms observed across variants include malicious Git hooks, Xcode project modifications, shell-profile changes, macOS preference storage, Launch Daemons, Dock-based execution, and trojanized applications. Recent variants also attempt to impair Apple security protections and telemetry, including XProtect, MRT, TCC-related controls, software-update functions, and CloudTelemetryService.
XCSSET collects browser credentials, cookies, session tokens, clipboard contents, screenshots, local files, application data, and data from applications including Safari, Chrome, Firefox, Telegram, Notes, Contacts, Evernote, Opera, Skype, and WeChat. It can use deceptive privilege prompts to obtain access to protected browser data. Newer variants hijack Chrome through the Chrome DevTools Protocol to intercept traffic, execute JavaScript in active sessions, capture autofill data, steal credentials and cookies, manipulate cryptocurrency-wallet transactions, and provide fileless remote command execution. XCSSET can also replace Telegram Desktop with a trojanized application. Collected data is encrypted and exfiltrated over its command-and-control channel. Earlier variants included command-directed file encryption and ransom-note display functionality. Activity has included heightened targeting of developers in South Asia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-30713 May 24 macOS TCC bypass abused by XCSSET malware
35 distinct techniques documented for this family, organized by ATT&CK tactic.
These Xcode projects have been modified such that upon building, these projects would run a malicious code. This eventually leads to the main XCSSET malware being dropped and run on the affected system.
The loader is a run-only compiled AppleScript, and theft modules are fetched from the C2 and executed in memory via osascript.
XCSSET injects a malicious preBuild hook into Android Gradle projects and a malicious build phase/build rule into Xcode projects.
printf xAxd | tr -d A reconstructs xxd at runtime to defeat string-based scanners; other payloads use altered base64/hex utilities and randomized encoding.
The persist module builds a fake app bundle, patches it to impersonate Launchpad, and swaps the real Launchpad Dock tile for it. Other modules create fake Safari and System Settings bundles.
Blocking the user from changing passwords but also stealing newly modified passwords
Using exploits, it abuses the existing the Safari and other installed browsers to steal user data. In particular, it Uses a vulnerability to read and dump Safari cookies
browser_remote exfiltrates Chrome cookies and session tokens, while safari_remote targets Safari local data.
It steals information from the user’s Evernote, Notes, Skype, Telegram, QQ ,and WeChat apps
browser_remote strips Chrome's Safe Storage keychain entry to intercept its regenerated encryption key and decrypt saved passwords, cookies, and session tokens; firefox_data collects Firefox credentials.
Copy “~/Library/Group Containers/6N38VWS5BX.ru.keepcoder.Telegram” folder from machine A to machine B, and replace the existing folder. Run Telegram on machine B. When this is done, it is already logged in with the same account used on machine A.
Stage 1 contacts the C2 and gets back a script that re-requests with the OS and username.
Stage 2 collects the hardware serial number and locale, while Stage 1 re-requests a script with the OS and username.
data_folders_finder exfiltrates files from targeted folders; notes_app exfiltrates Notes, Reminders, and Calendar data; tdesktop targets Telegram session data.
Blocking the user from changing passwords but also stealing newly modified passwords
We detected the entry threat as TrojanSpy.MacOS.XCSSET.A and its command and control (C&C) related files as Backdoor.MacOS.XCSSET.A ... hxxps://adobestats.com/ C&C Server hxxps://flixprice.com/ C&C Server
The decoded build-hook blob contacts C2 domains using curl; stolen data is sent to /u via multipart POST.
Examples include 'Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES,' 'Winnti for Linux has used a custom TCP protocol with four-byte XOR for command and control,' and 'XCSSET uses RC4 encryption over TCP to communicate with its C2 server.'
140 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
63 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular macOS worm that propagates by injecting malicious hooks into Android Gradle projects, Xcode projects, and Git pre-commit hooks. It establishes deceptive Dock-based persistence and retrieves in-memory modules from C2 infrastructure to steal browser credentials, cookies and tokens, Safari and Firefox data, Telegram sessions, Notes/Reminders/Calendar data, clipboard contents, and files from targeted user folders. It also impersonates System Settings in an attempt to obtain elevated privileges.
MacOS malware that infects Xcode developer projects, injects malicious code into local projects so payloads execute during build, and can propagate through shared repositories in a supply-chain-like manner. It steals browser cookies and credentials, abuses Safari including a UXSS-style JavaScript backdoor technique, steals data from apps such as Evernote, Notes, Skype, Telegram, QQ, and WeChat, takes screenshots, uploads files, and can encrypt files and display a ransom note on command.
XCSSET is a macOS malware family distributed via compromised Xcode projects and Git repositories. In the described campaign, version 40 uses a four-stage infection chain and 17 modules for credential theft, keystroke logging, clipboard manipulation, browser hijacking, data exfiltration, Chrome-based traffic interception, MetaMask transaction manipulation, reverse shell execution, and trojanizing Telegram Desktop, while also attempting to disable multiple macOS security protections.
Advanced macOS malware that targets Apple developers via Xcode supply-chain compromise. It infects legitimate Xcode projects, spreads across existing projects on compromised hosts, uses fileless persistence, dynamic in-memory execution, polymorphic payloads, and multi-layered obfuscation, and supports credential theft, browser hijacking, clipboard monitoring, data exfiltration, and rotating C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.