Close Menu
Daily Guardian
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
What's On

ZetaChain: The Private Memory Layer for AI

June 1, 2026

Quebec opens investigation into response of 2025 fatal police shooting of teen

June 1, 2026

The Google Pixel Watch 5 may have been spoiled by… the creator of Borderlands

June 1, 2026

Monument Reports Third Quarter Fiscal 2026 Results

June 1, 2026

Discovery Completes Acquisition of Kidd Operations

June 1, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian
Subscribe
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
Daily Guardian
Home » ADEX Investigation Reveals XCSSET Supply-Chain Threat Hidden in Xcode Build Files
Press Release

ADEX Investigation Reveals XCSSET Supply-Chain Threat Hidden in Xcode Build Files

By News RoomJune 1, 20263 Mins Read
ADEX Investigation Reveals XCSSET Supply-Chain Threat Hidden in Xcode Build Files
Share
Facebook Twitter LinkedIn Pinterest Email

Photo Courtesy of: ADEX

LIMASSOL, Cyprus, June 01, 2026 (GLOBE NEWSWIRE) — ADEX has published a first-hand investigation into an active XCSSET malware infection targeting macOS developer pipelines, revealing how the malware hides inside Xcode project build files and spreads through developer workflows.

The investigation examined a live infection on a macOS workstation used for iOS development. ADEX found that XCSSET was not embedded in a final application, but inside Xcode project configuration files known as project.pbxproj files. These files control build instructions in Xcode, Apple’s official development environment for macOS, iOS, iPadOS, watchOS, and tvOS applications.

XCSSET is a modular macOS malware family first identified in the Summer of 2020. It is distributed through compromised Xcode projects and triggered when a developer builds the project. Once activated, the malware can harvest credentials, collect browser session data, manipulate cryptocurrency wallet addresses copied to the clipboard, establish persistence, and infect other Xcode projects on the same machine.

During the investigation, ADEX identified repeated osascript executions from /tmp/jl, a temporary file that disappeared almost immediately after running. The team captured the file and found that it was a compiled AppleScript containing obfuscated payloads. After decoding the payload, ADEX found that the malware collected system information and exfiltrated it to the command-and-control domain riggletoy.ru.

ADEX also found that the malware had modified more than 20 Xcode projects on the affected workstation. The projects were changed within the same minute, indicating automated propagation across the machine. The investigation further identified persistence mechanisms, including a fake Launchpad.app placed in a user cache directory, as well as launch agents, shell profile injections, and git hooks.

The report explains that cleaning individual Xcode projects is not enough if the persistence layer remains active. According to ADEX, remediation should begin by removing all autostart points, including fake application files, rogue launch agents, shell profile injections, and git hooks. The system should then be rebooted before restoring Xcode projects from a known-clean git state.

ADEX’s investigation also reviewed public GitHub repositories and identified 24 repositories containing XCSSET payload chains. Examples included PrinceMittal1/DemoForAuthFlow, zzzznick/dummy-ios, and dvillegastech/ReaxBD. Twelve of the 24 repositories received commits in 2026, with the most recent just one day before inspection . The report also highlighted command-and-control domains including riggletoy.ru and netcdndev.in, with netcdndev.in described as a domain not previously found in public indicator lists at the time of the investigation.

ADEX recommends that developers manually inspect Xcode build phases before opening or building unfamiliar projects, and monitor project.pbxproj files in version control, check global git hooks, keep System Integrity Protection enabled, and use outbound firewall and persistence-monitoring tools.

For organizations, the report recommends behavioral endpoint detection on developer machines, regular auditing of third-party SDKs and dependencies, mobile device management controls, monitoring of launch agents and git hook settings, and regular rotation of API tokens. Any token stored on a compromised developer machine should be treated as exposed.

The full report positions XCSSET as a supply-chain threat because it targets the trusted relationship between developers, repositories, build systems, and downstream software users. Its effectiveness depends on hiding in build files that are commonly shared but rarely reviewed manually.

About ADEX

ADEX is a cybersecurity and fraud-prevention company focused on identifying, analyzing, and disrupting threats that affect digital businesses, developer environments, and advertising ecosystems. The company investigates malware, fraud infrastructure, account compromise, and supply-chain risks to help organizations detect exposure, strengthen defenses, and respond to active threats.

Contact Information:
Name: Michael Gor
Company: ADEX
Website: www.ADEX.com
Email: [email protected]

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/998ee963-165f-4be9-b322-fd16f82e775f

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

ZetaChain: The Private Memory Layer for AI

Monument Reports Third Quarter Fiscal 2026 Results

Discovery Completes Acquisition of Kidd Operations

Stocktwits Deepens Its Social Finance Leadership With All-New Symbol Pages Centered on Community Intelligence

HII’s Ingalls Shipbuilding Celebrates 2026 Class of Master Shipbuilders

ISG Enhances Technical Depth with Acquisition of R.E. Warner & Associates, a Firm Built on 75 Years of Legacy and Expertise

University of Miami Miller School of Medicine Names Dr. Pradeep Ramulu Chair of Ophthalmology and the Bascom Palmer Eye Institute

Thomas Global Systems Completes Supplier Qualification Testing of Crew Station Components for AH-64E Apache, Delivers Units For Boeing Testing

USCB Financial Holdings, Inc. Names Sergio Garrido Chief Credit Officer; Announces Retirement of William “Bill” Turner

Editors Picks

Quebec opens investigation into response of 2025 fatal police shooting of teen

June 1, 2026

The Google Pixel Watch 5 may have been spoiled by… the creator of Borderlands

June 1, 2026

Monument Reports Third Quarter Fiscal 2026 Results

June 1, 2026

Discovery Completes Acquisition of Kidd Operations

June 1, 2026

Latest News

Stocktwits Deepens Its Social Finance Leadership With All-New Symbol Pages Centered on Community Intelligence

June 1, 2026

HII’s Ingalls Shipbuilding Celebrates 2026 Class of Master Shipbuilders

June 1, 2026

Nova Scotia’s flat funding blamed for closure of five Annapolis Valley libraries

June 1, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian Canada. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version