XCSSET has returned with a way to target macOS developers. The latest version, v40, hides inside poisoned Xcode projects and can turn a local build into a supply-chain compromise. Once activated, it can spread through other projects, raising risk for developers and the organizations that use their code. The malware family was first documented in 2020, but its campaign shows a move toward stealth and scale. It uses memory-based execution, changing payloads, and short-lived files to reduce visible traces. Developers across South Asia have seen heightened targeting, while infected projects have appeared in open-source repositories and workflows. Unit 42 analysts identified the v40 activity in mid-April 2026 and observed a second...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!