Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Microsoft flags dangerous XCSSET macOS malware targeting developers – so be on your guard

Tech Wavo by Tech Wavo
September 26, 2025
in Computers
0




  • Microsoft detects upgraded XCSSET macOS backdoor used in limited targeted attacks
  • New variant steals Firefox data and hijacks clipboard to redirect cryptocurrency transactions
  • Apple and GitHub are removing malicious repositories linked to the campaign

Microsoft is warning about a new variant of a known macOS backdoor which builds on previous iterations by providing additional capabilities for the attackers.

In its latest report, Microsoft Threat Intelligence claims to have seen an upgraded XCSSET macOS backdoor being used in “limited attacks”.

Developers who unknowingly used these compromised projects would build and run their apps, which triggered the malware. Once inside the system, XCSSET would quietly install itself and begin stealing sensitive data like browser cookies, credentials, and messages. It would also hijack Safari and other browsers to inject malicious code and bypass security protections.


You may like

Targeting Firefox and the clipboard

XCSSET was first spotted in 2020, and is primarily known for infecting Xcode development projects used by macOS developers.

Xcode is Apple’s official integrated development environment (IDE) for building apps on macOS, iOS, iPadOS, watchOS, and tvOS.

Five years later, Microsoft spotted a new version of XCSSET, with a few notable changes.

First, it can now steal Firefox browser data, too, by installing a modified build of the open-source HackBrowserData tool.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Second, it comes with a component that can hijack the clipboard – a usual practice for criminals looking to steal people’s cryptocurrency.

When the malware detects a crypto address in the clipboard, it will replace it with the one belonging to the attackers, so that when the victim wants to copy and paste the receiver address, they actually end up sending money to the attackers.

Finally, the malware comes with a new persistence method, making sure it remains hidden on the compromised device, for longer.

The good news is that Microsoft only saw it in limited attacks, meaning it hasn’t yet made significant damage. It already notified both Apple and GitHub, who are now working on removing the repositories linked to the campaign.

Via BleepingComputer

You might also like

Previous Post

How Carvana is trying to fix the broken car buying world

Next Post

Caffeine Tracker Alyx Uses Visual Lookup to Easily Log Your Intake

Next Post
Caffeine Tracker Alyx Uses Visual Lookup to Easily Log Your Intake

Caffeine Tracker Alyx Uses Visual Lookup to Easily Log Your Intake

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Caffeine Tracker Alyx Uses Visual Lookup to Easily Log Your Intake

by Tech Wavo
September 26, 2025
0
Caffeine Tracker Alyx Uses Visual Lookup to Easily Log Your Intake
Apps

One of the best ways to use the app is with Visual Lookup. Just take a picture of a caffeinated...

Read more

Microsoft flags dangerous XCSSET macOS malware targeting developers – so be on your guard

by Tech Wavo
September 26, 2025
0
Microsoft flags dangerous XCSSET macOS malware targeting developers – so be on your guard
Computers

Microsoft detects upgraded XCSSET macOS backdoor used in limited targeted attacksNew variant steals Firefox data and hijacks clipboard to redirect...

Read more

How Carvana is trying to fix the broken car buying world

by Tech Wavo
September 26, 2025
0
How Carvana is trying to fix the broken car buying world
Computers

Buying a car in America is usually a hellish experience involving pushy salespeople, mysterious fees, and hours-long financing negotiations. That’s...

Read more

Could These Eye Drops End the Need for Reading Glasses?

by Tech Wavo
September 26, 2025
0
Could These Eye Drops End the Need for Reading Glasses?
Computers

The Stats don’t lie: after age 65, most people will struggle to focus visually on close-up objects. You might have...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock