• Sources: Unit 42 analysis, HN discussion
  • Summary: Unit 42 reports XCSSET v40 spreading through the Xcode projects of legitimate apps since April 2026, with infection triggered when a developer builds an infected project locally and the variant then worming into every Xcode project on the host. It disables the macOS SoftwareUpdate configuration channel covering XProtect, MRT, TCC, and Rapid Security Response, holds an exclusive file lock on the XProtect signature database, terminates CloudTelemetryService, and calls tccutil reset AppleEvents to re-prompt for automation while masquerading as System Settings or Xcode. A new Chrome module abuses the Chrome DevTools Protocol for a fileless reverse shell and MetaMask transaction rewriting, a further new module replaces Telegram.app with an ad hoc signed trojanized copy, and Unit 42 reported the Chrome behavior to Google, which protects against it on Windows and is extending the protection to macOS. The analysis enumerates no affected macOS or Xcode version numbers, so the version scope of an exposed build host is not stated.
  • Why it matters: An infected build host stops receiving the signature updates that would detect the infection, so a developer machine that compiles one untrusted Xcode project loses both the detection and the update path at the same time.

send feedback on this story