Dev.to
8/1/2026

XCSSET v40: From Xcode Supply Chain to Memory-Resident and Browser/Telegram Hijacking
Short summary
Unit 42 details XCSSET v40, a macOS supply chain malware that injects malicious run-scripts into legitimate Xcode projects on GitHub. After C2 approval, it executes 17 in-memory modules to hijack Chrome sessions via DevTools Protocol and replace Telegram with a trojanized version. The malware self-replicates into other local Xcode projects, spreading to additional developers and build artifacts.
- •XCSSET v40 injects malicious scripts into Xcode projects from GitHub
- •17 in-memory modules steal Chrome cookies and replace Telegram with trojanized app
- •Self-replicates across local Xcode projects to spread to other developers
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



