A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories.
Xcode is the official software development kit (SDK) for creating, testing, and publishing software for all Apple's platforms.
After months of inactivity, XCSSET has resurfaced with an updated version, v40, that features enhanced evasion techniques and introduces two new components, researchers have found.
Researchers at Palo Alto Networks' Unit 42, who analyzed the infection chain, say the threat actor spreads the malware by compromising vulnerable Git repositories and injecting a downloader script into benign files within Xcode projects.
Developers downloading the compromised projects become infected upon building them, allowing XCSSET to compromise every other Xcode project on the system and propagate further through shared source code.








