Palo Alto Networks Identifies Advanced XCSSET Malware Targeting macOS Developers
Palo Alto Networks' Unit 42 has identified a new version of the XCSSET malware, version 40 (v40), which targets the macOS ecosystem. This malware is particularly insidious as it hides its core logic in memory space, making it difficult to detect. The malware spreads through supply chain attacks by embedding itself in Xcode projects, which are used by developers to build applications for Apple's operating systems. The latest version enhances its evasion capabilities by using polymorphic payload generation and fileless persistence. It also weakens several security mechanisms on affected machines. The malware has been spreading since April 2026, primarily targeting developers in South Asia. It can infect all existing Xcode projects on a compromised system, maximizing its impact. Palo Alto Networks has developed advanced AI and pattern-matching algorithms to de-obfuscate the malware's logic and provide mitigation strategies.