Close Menu
Daily Guardian
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
What's On

2 dead after plane crash, fire near Fergus, Ont.

October 10, 2026

Ledger wallet tampering suspected after reports of crypto thefts

October 10, 2026

Lotto Max jackpot set for $85M, largest prize in history of Canadian lotto

October 10, 2026

LG’s RGB LED TV is good for certain situations, but an OLED is better

October 10, 2026

Tension peaking among Albertans on separation vote

October 10, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian
Subscribe
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
Daily Guardian
Home » ADEX Investigation Reveals XCSSET Supply-Chain Threat Hidden in Xcode Build Files
Press Release

ADEX Investigation Reveals XCSSET Supply-Chain Threat Hidden in Xcode Build Files

By News RoomJune 1, 20263 Mins Read
ADEX Investigation Reveals XCSSET Supply-Chain Threat Hidden in Xcode Build Files
Share
Facebook Twitter LinkedIn Pinterest Email

Photo Courtesy of: ADEX

LIMASSOL, Cyprus, June 01, 2026 (GLOBE NEWSWIRE) — ADEX has published a first-hand investigation into an active XCSSET malware infection targeting macOS developer pipelines, revealing how the malware hides inside Xcode project build files and spreads through developer workflows.

The investigation examined a live infection on a macOS workstation used for iOS development. ADEX found that XCSSET was not embedded in a final application, but inside Xcode project configuration files known as project.pbxproj files. These files control build instructions in Xcode, Apple’s official development environment for macOS, iOS, iPadOS, watchOS, and tvOS applications.

XCSSET is a modular macOS malware family first identified in the Summer of 2020. It is distributed through compromised Xcode projects and triggered when a developer builds the project. Once activated, the malware can harvest credentials, collect browser session data, manipulate cryptocurrency wallet addresses copied to the clipboard, establish persistence, and infect other Xcode projects on the same machine.

During the investigation, ADEX identified repeated osascript executions from /tmp/jl, a temporary file that disappeared almost immediately after running. The team captured the file and found that it was a compiled AppleScript containing obfuscated payloads. After decoding the payload, ADEX found that the malware collected system information and exfiltrated it to the command-and-control domain riggletoy.ru.

ADEX also found that the malware had modified more than 20 Xcode projects on the affected workstation. The projects were changed within the same minute, indicating automated propagation across the machine. The investigation further identified persistence mechanisms, including a fake Launchpad.app placed in a user cache directory, as well as launch agents, shell profile injections, and git hooks.

The report explains that cleaning individual Xcode projects is not enough if the persistence layer remains active. According to ADEX, remediation should begin by removing all autostart points, including fake application files, rogue launch agents, shell profile injections, and git hooks. The system should then be rebooted before restoring Xcode projects from a known-clean git state.

ADEX’s investigation also reviewed public GitHub repositories and identified 24 repositories containing XCSSET payload chains. Examples included PrinceMittal1/DemoForAuthFlow, zzzznick/dummy-ios, and dvillegastech/ReaxBD. Twelve of the 24 repositories received commits in 2026, with the most recent just one day before inspection . The report also highlighted command-and-control domains including riggletoy.ru and netcdndev.in, with netcdndev.in described as a domain not previously found in public indicator lists at the time of the investigation.

ADEX recommends that developers manually inspect Xcode build phases before opening or building unfamiliar projects, and monitor project.pbxproj files in version control, check global git hooks, keep System Integrity Protection enabled, and use outbound firewall and persistence-monitoring tools.

For organizations, the report recommends behavioral endpoint detection on developer machines, regular auditing of third-party SDKs and dependencies, mobile device management controls, monitoring of launch agents and git hook settings, and regular rotation of API tokens. Any token stored on a compromised developer machine should be treated as exposed.

The full report positions XCSSET as a supply-chain threat because it targets the trusted relationship between developers, repositories, build systems, and downstream software users. Its effectiveness depends on hiding in build files that are commonly shared but rarely reviewed manually.

About ADEX

ADEX is a cybersecurity and fraud-prevention company focused on identifying, analyzing, and disrupting threats that affect digital businesses, developer environments, and advertising ecosystems. The company investigates malware, fraud infrastructure, account compromise, and supply-chain risks to help organizations detect exposure, strengthen defenses, and respond to active threats.

Contact Information:
Name: Michael Gor
Company: ADEX
Website: www.ADEX.com
Email: [email protected]

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/998ee963-165f-4be9-b322-fd16f82e775f

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

vineyard vines Returns as Official Style of the Head Of The Charles® Regatta

Bigger & Better Than Ever: Laxmi & Chef Kunal Kapur Return With ‘Diwali Delights’ Season 2

2026 Chery International User Summit to Kick Off: LUXEED Set for Global Brand Launch

Going Asset Management Wins Capital’s Excellence Fund Award, Harnessing Technology to Enhance the Long-Term Value of Assets

Alation Honors 2026 AI Radicals Award Winners at revAlation

Supported Employment: Helping Individuals Build Meaningful Careers

“The Carbon Pursuit of Happiness” Premieres October 10: A New Chapter for In-Depth Dialogue on Health and Humanity

Evolution Metals & Technologies Corp. Raises Fiscal 2026 Revenue Guidance 62% at Midpoint to 11 Million and Reaffirms 460 Million Fiscal 2027 Outlook

Ufunded Launches “Spotlight” Series, Documenting the Minds Shaping Modern Trading

Editors Picks

Ledger wallet tampering suspected after reports of crypto thefts

October 10, 2026

Lotto Max jackpot set for $85M, largest prize in history of Canadian lotto

October 10, 2026

LG’s RGB LED TV is good for certain situations, but an OLED is better

October 10, 2026

Tension peaking among Albertans on separation vote

October 10, 2026

Latest News

Anthropic is cutting off its internal evaluations from the internet

October 10, 2026

Provinces call on Ottawa to expand mining credit

October 10, 2026

Support pours in for tortoise ahead of surgery

October 10, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian Canada. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version