Feed›Threat Intelligence›XCSSET malware returns in macOS attacks that hijack Chrome...
Threat IntelligenceCyber Insider
8.0 — CRITICAL

XCSSET malware returns in macOS attacks that hijack Chrome

📅 4 August 2026 at 14:30 UTC📰 Cyber InsiderView original source ↗
XCSSET malware returns in macOS attacks that hijack Chrome

A new version of the XCSSET macOS malware can hijack Google Chrome, intercept browser activity, and turn the browser into a fileless command channel. The campaign has been spreading through infected Xcode projects since April 2026, targeting software developers and users of the applications they build. Palo Alto Networks Unit 42 researchers began tracking the … The post XCSSET malware returns in macOS attacks that hijack Chrome appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A new variant of XCSSET malware has been detected, targeting macOS users and hijacking Google Chrome, allowing attackers to intercept browser activity and turn the browser into a fileless command channel.

⚙️Technical Details
Affected Systems
macOS
Attack Vectors
infected Xcode projects, Git repositories, and Chrome DevTools Protocol abuse
💥Impact Assessment
Severity: high
Who Is at Risk
software developers and users of applications they build, particularly those in South Asia with thousands of active users
🛡️Recommended Actions
1Monitor Xcode projects and open-source dependencies before building projects from them
2Investigate Chrome launches using unexpected remote-debugging arguments
3Alert on unusual AppleScript, defaults utility, or ad hoc code-signing activity
📦Affected Products
Software:XcodeChrome

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider ↗
← Back to feed