Close Menu
Daily Guardian
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
What's On

University of Miami Miller School of Medicine Names Dr. Pradeep Ramulu Chair of Ophthalmology and the Bascom Palmer Eye Institute

June 1, 2026

Thomas Global Systems Completes Supplier Qualification Testing of Crew Station Components for AH-64E Apache, Delivers Units For Boeing Testing

June 1, 2026

USCB Financial Holdings, Inc. Names Sergio Garrido Chief Credit Officer; Announces Retirement of William “Bill” Turner

June 1, 2026

Le Vian® Reveals the Five Jewelry Trends Defining 2027 at JCK Las Vegas

June 1, 2026

Pet Butler Promotes Angela Meyers to Brand President

June 1, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian
Subscribe
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
Daily Guardian
Home » ADEX Investigation Reveals XCSSET Supply-Chain Threat Hidden in Xcode Build Files
Press Release

ADEX Investigation Reveals XCSSET Supply-Chain Threat Hidden in Xcode Build Files

By News RoomJune 1, 20263 Mins Read
ADEX Investigation Reveals XCSSET Supply-Chain Threat Hidden in Xcode Build Files
Share
Facebook Twitter LinkedIn Pinterest Email

Photo Courtesy of: ADEX

LIMASSOL, Cyprus, June 01, 2026 (GLOBE NEWSWIRE) — ADEX has published a first-hand investigation into an active XCSSET malware infection targeting macOS developer pipelines, revealing how the malware hides inside Xcode project build files and spreads through developer workflows.

The investigation examined a live infection on a macOS workstation used for iOS development. ADEX found that XCSSET was not embedded in a final application, but inside Xcode project configuration files known as project.pbxproj files. These files control build instructions in Xcode, Apple’s official development environment for macOS, iOS, iPadOS, watchOS, and tvOS applications.

XCSSET is a modular macOS malware family first identified in the Summer of 2020. It is distributed through compromised Xcode projects and triggered when a developer builds the project. Once activated, the malware can harvest credentials, collect browser session data, manipulate cryptocurrency wallet addresses copied to the clipboard, establish persistence, and infect other Xcode projects on the same machine.

During the investigation, ADEX identified repeated osascript executions from /tmp/jl, a temporary file that disappeared almost immediately after running. The team captured the file and found that it was a compiled AppleScript containing obfuscated payloads. After decoding the payload, ADEX found that the malware collected system information and exfiltrated it to the command-and-control domain riggletoy.ru.

ADEX also found that the malware had modified more than 20 Xcode projects on the affected workstation. The projects were changed within the same minute, indicating automated propagation across the machine. The investigation further identified persistence mechanisms, including a fake Launchpad.app placed in a user cache directory, as well as launch agents, shell profile injections, and git hooks.

The report explains that cleaning individual Xcode projects is not enough if the persistence layer remains active. According to ADEX, remediation should begin by removing all autostart points, including fake application files, rogue launch agents, shell profile injections, and git hooks. The system should then be rebooted before restoring Xcode projects from a known-clean git state.

ADEX’s investigation also reviewed public GitHub repositories and identified 24 repositories containing XCSSET payload chains. Examples included PrinceMittal1/DemoForAuthFlow, zzzznick/dummy-ios, and dvillegastech/ReaxBD. Twelve of the 24 repositories received commits in 2026, with the most recent just one day before inspection . The report also highlighted command-and-control domains including riggletoy.ru and netcdndev.in, with netcdndev.in described as a domain not previously found in public indicator lists at the time of the investigation.

ADEX recommends that developers manually inspect Xcode build phases before opening or building unfamiliar projects, and monitor project.pbxproj files in version control, check global git hooks, keep System Integrity Protection enabled, and use outbound firewall and persistence-monitoring tools.

For organizations, the report recommends behavioral endpoint detection on developer machines, regular auditing of third-party SDKs and dependencies, mobile device management controls, monitoring of launch agents and git hook settings, and regular rotation of API tokens. Any token stored on a compromised developer machine should be treated as exposed.

The full report positions XCSSET as a supply-chain threat because it targets the trusted relationship between developers, repositories, build systems, and downstream software users. Its effectiveness depends on hiding in build files that are commonly shared but rarely reviewed manually.

About ADEX

ADEX is a cybersecurity and fraud-prevention company focused on identifying, analyzing, and disrupting threats that affect digital businesses, developer environments, and advertising ecosystems. The company investigates malware, fraud infrastructure, account compromise, and supply-chain risks to help organizations detect exposure, strengthen defenses, and respond to active threats.

Contact Information:
Name: Michael Gor
Company: ADEX
Website: www.ADEX.com
Email: [email protected]

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/998ee963-165f-4be9-b322-fd16f82e775f

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

University of Miami Miller School of Medicine Names Dr. Pradeep Ramulu Chair of Ophthalmology and the Bascom Palmer Eye Institute

Thomas Global Systems Completes Supplier Qualification Testing of Crew Station Components for AH-64E Apache, Delivers Units For Boeing Testing

USCB Financial Holdings, Inc. Names Sergio Garrido Chief Credit Officer; Announces Retirement of William “Bill” Turner

Le Vian® Reveals the Five Jewelry Trends Defining 2027 at JCK Las Vegas

Pet Butler Promotes Angela Meyers to Brand President

Blue Sky and Sincerely Jules Bring Vintage Style to Academic Planners at Staples

Bitdeer Launches SEALMINER DL1 Hydro Achieving 52.5 GH/s and 149 J/GH Power Efficiency

How to Trade Memecoins with AI: A Beginner’s Guide Using MemeToro Technology

Sompo appoints Bart Van Gysegem Country Manager, Insurance for Belgium and the Netherlands

Editors Picks

Thomas Global Systems Completes Supplier Qualification Testing of Crew Station Components for AH-64E Apache, Delivers Units For Boeing Testing

June 1, 2026

USCB Financial Holdings, Inc. Names Sergio Garrido Chief Credit Officer; Announces Retirement of William “Bill” Turner

June 1, 2026

Le Vian® Reveals the Five Jewelry Trends Defining 2027 at JCK Las Vegas

June 1, 2026

Pet Butler Promotes Angela Meyers to Brand President

June 1, 2026

Latest News

Blue Sky and Sincerely Jules Bring Vintage Style to Academic Planners at Staples

June 1, 2026

Bitdeer Launches SEALMINER DL1 Hydro Achieving 52.5 GH/s and 149 J/GH Power Efficiency

June 1, 2026

How to Trade Memecoins with AI: A Beginner’s Guide Using MemeToro Technology

June 1, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian Canada. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version