The Flutter package universal_file_viewer version 0.1.5 was published to pub.dev with XCSSET malware embedded in its example-project files. Its Dart library code was clean, so consuming the package as a dependency does not execute the payload; exposure occurs when developers clone the repository and build the example app locally. The infection appears to have originated from the maintainer's already compromised workstation rather than a targeted takeover of the package or its users.
The malicious files inject Android Gradle, Xcode, and Git pre-commit hooks that contact command-and-control infrastructure and can spread to other developer projects. XCSSET is a macOS-focused developer supply-chain malware family that has evolved to steal browser data—including Safari and Firefox credentials, cookies, and history—Telegram, notes, clipboard contents, and local files; it can also replace copied cryptocurrency wallet addresses. The package sample uses disguised Dock-based persistence and AES-256-CBC-encrypted data exfiltration, while recent XCSSET variants have added stronger persistence, stealthy AppleScript-based execution, and expanded Xcode-project propagation.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft's September 2025 analysis referenced changes to XCSSET that had previously been described in a March 2025 Microsoft blog post, including obfuscation and persistence techniques for infecting Xcode projects.
The infection included malicious Android Gradle preBuild hooks, Xcode PBXBuildRule entries, and Git pre-commit hooks that contact C2 infrastructure and can propagate into other Android, Xcode, and Git projects. The reported payload also establishes disguised persistence and steals browser, messaging, clipboard, notes, and local-file data for AES-256-CBC-encrypted exfiltration.
The pub.dev package universal_file_viewer version 0.1.5 was found to include XCSSET-infected files in its example directory after being traced to a compromised GitHub repository. Its Dart library code was clean, and ordinary dependency installation did not execute the malicious code; risk arose when building the cloned example project locally.
Microsoft shared its XCSSET findings with Apple and worked with GitHub to remove infected repositories associated with the campaign.
The newly analyzed XCSSET variant added a Firefox-focused stealer based on a modified HackBrowserData binary and a persistence module that creates a LaunchDaemon and can disable macOS update protections. It can also replace copied cryptocurrency wallet addresses with attacker-controlled addresses based on C2-supplied patterns.
Microsoft Threat Intelligence identified a new XCSSET variant in the wild that infects Xcode projects during builds and adds browser-data theft, cryptocurrency clipboard hijacking, and enhanced persistence. Microsoft said the activity had been observed only in limited attacks at the time of its analysis.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 30 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
aikido.dev
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.