AUGUST 12, 2026
Subscribe
Global Press Media · World Report
Technology

New XCSSET Variant Leverages Chrome DevTools Protocol for Developer Supply Chain Attacks

New XCSSET Variant Leverages Chrome DevTools Protocol for Developer Supply Chain Attacks

A sophisticated malware campaign, identified as XCSSET v40, has re-emerged, specifically targeting macOS developers by embedding itself within legitimate Xcode projects. This latest iteration is designed to exploit the Chrome DevTools Protocol, enabling it to steal sensitive cookies and execute arbitrary commands on compromised systems, posing a significant risk of supply-chain compromise.

The threat actors behind XCSSET v40 have refined their distribution method, luring developers into downloading or cloning seemingly benign Xcode projects that have been secretly "poisoned." When a developer builds such a project locally, the malware activates, transforming their development environment into a potential launchpad for wider attacks.

A key innovation in XCSSET v40 is its abuse of the Chrome DevTools Protocol. This protocol is typically used by developers for debugging web applications, offering deep access to browser functions and data. XCSSET v40 subverts this legitimate tool, hijacking its capabilities to illicitly exfiltrate user cookies from the Chrome browser and run malicious commands directly on the developer's machine without their knowledge.

Editorial Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related