


Perceptive Security
SOC/SIEM Consultancy

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
Published:
31 July 2026 at 12:00:18
Alert date:
31 July 2026 at 18:01:19
Source:
unit42.paloaltonetworks.com
Operating Systems, Ransomware & Malware, Supply Chain & Dependencies
Unit 42 researchers conducted a deep-dive analysis of XCSSET v40, a sophisticated macOS malware that targets software developers through infected Xcode projects. The malware, dubbed the 'Xcode Assassin', has returned in a new version with updated capabilities. Unit 42 leveraged advanced pattern matching techniques and AI-assisted analysis to decode the malware's obfuscated logic and understand its behavior. XCSSET spreads by embedding malicious code into Xcode projects, potentially allowing it to propagate through developer supply chains when infected projects are shared. The analysis highlights the ongoing threat XCSSET poses to the macOS developer ecosystem and underscores the need for heightened vigilance among developers using Xcode.
Technical details
Mitigation steps:
Affected products:
macOS
Xcode
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
