Microsoft Threat Intelligence reports that a new variant of the XCSSET malware for macOS has been detected in limited attacks, incorporating several new features, including improved browser targeting, clipboard tracking, and improved persistence mechanisms.

XCSSET is a modular macOS malware that acts as an information and cryptocurrency thief, stealing Notes, cryptocurrency wallets , and browser data from infected devices. It spreads by seeking out and infecting other Xcode projects on the device, so that the malware is executed when the project is built.
See also: North Korean hackers use new AkdoorTea backdoor
“The XCSSET malware is designed to infect Xcode projects, which are commonly used by software developers. It executes when building an Xcode project,” Microsoft explains. “We believe this infection and propagation method relies on project files shared between developers building Apple or macOS-related applications.”
XCSSET macOS malware: New variant
In a new variant spotted by Microsoft, researchers have noted several changes. Now, the malware attempts to steal browser Firefox by installing a modified version of the open-source tool HackBrowserData. This tool is used to decrypt and extract browser data from browser data stores.

The new variant also includes an update to the clipboard-hijacking component, which monitors the macOS clipboard for regular expression patterns associated with cryptocurrency addresses. When a cryptocurrency address is detected, it replaces the address with one belonging to the attacker. This results in any cryptocurrency sent by the user to an infected device being sent to the attackers instead.
See also: New LockBit 5.0 ransomware targets Windows, Linux and ESXi
The malware also includes new persistence, such as creating LaunchDaemon entries that execute a ~/.root payload and create a fake System Settings.app in /tmp to mask its activity.
The new variant is not yet widespread, and Microsoft says it has only seen it in limited attacks. The researchers have also shared their findings with Apple and are working with GitHub to remove the associated repositories.
To protect yourself from this type of malware, it is recommended to keep macOS and applications up to date, especially considering that XCSSET has previously exploited vulnerabilities, including zero-days. Microsoft also recommends that developers always inspect Xcode projects before building them, especially when they have been shared with others.
Apple offers some built-in security features, such as Gatekeeper and XProtect to prevent infection.
See also: COLDRIVER group distributes new backdoor BAITSWITCH

macOS malware protection
But there are some other methods of protection:
- Keep your operating system and software up to date to patch any known vulnerabilities
- Be cautious when downloading and opening attachments or files from unknown sources
- Use a reliable antivirus software, especially if you frequently download files from the Internet.
- Enable FileVault, which encrypts your data and protects it in case of theft or unauthorized access.
- Regularly back up your important files to an external hard drive
The discovery of a new variant of XCSSET confirms that the macOS ecosystem is no longer the “safe haven” it is often portrayed to be. This malware does not just target the end user but also infiltrates the development environment itself, exploiting the trust between developers. This means that attacks can silently escalate, penetrating projects that end up in applications used by millions of users. This development shows how critical it is for Apple to further strengthen its built-in security measures and for developers to adopt “zero trust” practices in code management.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
