XcodeSpy is a macOS malware campaign centered on trojanized Xcode projects used to target Apple software developers. It abuses Xcode’s Run Script build-phase functionality so that opening or building a malicious project executes hidden shell logic and installs a customized variant of the EggShell backdoor. The malware has been associated with a doctored copy of a legitimate open-source Xcode project and represents a developer-focused supply-chain style intrusion vector.
On infected systems, XcodeSpy deploys a persistent backdoor on macOS, commonly using LaunchAgents for persistence and masquerading its components as Apple-related files and directories. The customized EggShell payload provides remote access and surveillance capabilities, including keylogging, microphone and camera recording, screen capture, file upload and download, and clipboard access. It also supports broader post-compromise activity through backdoor functionality and covert data collection.
XcodeSpy is notable for targeting developers rather than general consumers, making it relevant to software supply-chain risk and espionage-oriented operations. Reporting has linked the campaign to custom EggShell samples active in 2020, with at least one confirmed victim in a U.S. organization and indications of additional targeting in Asia. The operation has been discussed in connection with suspected North Korean threat activity, but attribution remains cautious. XcodeSpy illustrates how trusted development workflows and shared project files can be weaponized to gain initial access and establish long-term surveillance on macOS endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan embedded in tampered Xcode projects targeting developers, establishing a persistent backdoor.
A trojanized Xcode project targeting Apple developers via Xcode’s Run Script feature. It executes an obfuscated script, contacts attacker C2, drops a custom EggShell backdoor, establishes persistence with LaunchAgents, and enables microphone, camera, keyboard capture, plus file upload/download.
Referenced as the malware campaign/tooling in which a customized EggShell RAT variant was used.
Malware that targets macOS developers by infecting Xcode projects with a malicious script, which installs the EggShell backdoor for remote access and surveillance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.