Xcode Malware Now Spreads Across Local Projects

One infected developer machine can now contaminate multiple Xcode projects on that box, so the real blast radius is the workstation, not the single repository that first carried the malware. XCSSET v40 hides its core logic in memory and can worm into every existing Xcode project on a compromised macOS system, which turns routine local builds into a downstream supply-chain path. Unit 42 says v40 returned after months of dormancy and has been spreading since early April 2026 through Xcode projects in legitimate apps. The family targets software developers in the Apple ecosystem, and this version adds stronger stealth, fileless persistence, and broader worming across local projects. That changes cleanup. Reviewing one tainted project is not enough if the developer endpoint still holds the infection and can reseed other codebases. Teams that open third-party repositories or keep multiple local projects on the same Mac face a wider build-and-release risk than a normal project-level review catches.

Part of the PlainSec briefing for 2026-07-31

Sources