XcodeGhost is a software supply-chain malware operation centered on trojanized copies of Apple’s Xcode development environment. The malicious Xcode packages were distributed to developers, particularly in China, through unofficial mirrors and file-sharing services that offered faster downloads than Apple’s infrastructure. Developers who built iOS applications with the altered toolchain unknowingly compiled malicious code into their apps, allowing the malware to propagate downstream to end users through otherwise legitimate applications, including apps that reached Apple’s App Store.
The malicious modifications were embedded in repackaged Xcode releases and abused Xcode’s default framework search behavior so that an added Mach-O object file was linked into compiled applications without the developer’s awareness. Once an infected application executed on iOS, the implanted code collected device and application metadata such as app identity, device characteristics, locale information, timing data, and network context, then encrypted and transmitted that information to attacker-controlled infrastructure over HTTP. XcodeGhost also supported user-deception behavior by displaying fake alert dialogs that could be used to phish credentials.
XcodeGhost is notable as an early large-scale compromise of Apple’s software development ecosystem and a prominent example of compiler or build-environment malware. The incident demonstrated that compromising developer tooling can bypass normal trust assumptions around signed applications and app-store distribution. Risk extended beyond public App Store software to enterprise-distributed iOS applications and potentially to Apple-platform software built outside Apple’s review pipeline. The campaign primarily affected Apple developer workflows and iOS applications, with broader implications for macOS development environments because the compromised toolchain itself ran on Apple desktop systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
XcodeGhost is the first compiler malware in OS X. Its malicious code is located in a Mach-O object file that was repackaged into some versions of Xcode installers. These malicious installers were then uploaded to Baidu’s cloud file sharing service for used by Chinese iOS/OS X developers.
XcodeGhost implemented malicious code in its own CoreServices object file, and copies this file to a specific position that is one of Xcode’s default framework search paths. Hence, the code in the malicious CoreServices file will be added into any iOS app compiled with the infected Xcode without the developers’ knowledge.
By searching for “Xcode 下载” (Xcode downloading) in Google... these posts provided links to download all versions of Xcode from 6.0 to 7.0... All of the links direct to Baidu Yunpan... we found that all versions of Xcode between 6.1 to 6.4 were infected.
When an infected app is executed... malicious code will collect some system and app information... The collected information includes: Current time, Current infected app’s name, The app’s bundle identifier, Current device’s name and type, Current system’s language and country, Current device’s UUID, Network type
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as historical comparison: a trojanized Xcode distribution that injected malicious code into compiled iOS apps and enabled clipboard access, URL opening, and data exfiltration.
A trojanized/fake Xcode development environment used to inject malicious code into legitimate iOS/macOS apps, which can then be distributed via official app stores as a supply-chain compromise.
iOS malware that can display fake alert dialogs to phish user credentials.
Referenced as a historical example of a software supply-chain attack affecting iOS apps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.