top of page
perceptive_background_267k.jpg

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

Published:

31 July 2026 at 10:00:18

Alert date:

31 July 2026 at 16:01:19

Source:

unit42.paloaltonetworks.com

Click to open the original link from this advisory

Operating Systems, Ransomware & Malware, Supply Chain & Dependencies

Unit 42 researchers conducted a deep-dive analysis of XCSSET v40, a sophisticated macOS malware that targets software developers through infected Xcode projects. The malware, dubbed the 'Xcode Assassin', has returned in a new version with updated capabilities. Unit 42 leveraged advanced pattern matching techniques and AI-assisted analysis to decode the malware's obfuscated logic and understand its behavior. XCSSET spreads by embedding malicious code into Xcode projects, potentially allowing it to propagate through developer supply chains when infected projects are shared. The analysis highlights the ongoing threat XCSSET poses to the macOS developer ecosystem and underscores the need for heightened vigilance among developers using Xcode.

Technical details

Mitigation steps:

Affected products:

macOS
Xcode

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page