• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Security personnel discovered that Mac applications were implanted with XCSSET malware, which may evade security detection and penetrate the App Store

Security personnel discovered that Mac applications were implanted with XCSSET malware, which may evade security detection and penetrate the App Store

Claire by Claire
August 25, 2020 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

last week,Trend MicroSecurity researchers have discovered a serious new macOS malware that uses zero-day vulnerabilities to abnormally infect Xcode-related development projects. Now security researchers have further revealed more relevant details about this new malware. It may even escape the detection of Apple’s review team and penetrate into the Mac’s App Store. The impact cannot be ignored.

Security personnel discovered that Mac applications were implanted with XCSSET malware, which may evade security detection and penetrate the App Store

This new type of malware is a member of the XCSSET family. What makes it unique is that it is embedded into Xcode and starts running malicious code during the developer’s project construction phase, just like the ubiquitous gopher hiding in the garden soil. The discovery poses a huge risk to Xcode developers, as security researchers examine developers affected by the malware who share their projects through GitHub, making other users who rely on their own projects also vulnerable to potential supply chain attacks.

The malware is spread via infected Xcode projects because it can create maliciously modified applications and then deliver the Trojan horse. Specifically, it can abuse Safari and other browsers to steal data, exploit vulnerabilities to read and dump cookies, use Javascript to build backdoors into the system and then modify displayed websites, steal private banking information, prevent password changes, and steal newly changed passwords. In addition, security personnel also discovered that this malicious program can steal messages and screenshots from applications such as Evernote, Notes, Skype, Telegram, QQ and WeChat, upload files to the attacker’s designated server, or encrypt and lock files and display ransom notes. What makes this malware particularly dangerous is that currently commonly used verification methods (such as checking hashes) cannot identify the infection, and the developers are not aware that they are distributing the malware.

After further research, security researchers Oleksandr Shatkivskyi and Vlad Felenuik believe that the macOS App Store review team will most likely not be able to detect applications containing XCSSET malicious code. Since the security researchers did not have access to test the Mac Developer tool that comes with Apple Silicon, they believe that the malware will work on Mac devices equipped with Apple Silicon. Despite the seriousness of the XCSSET malware, they still believe macOS is a safe operating system and are optimistic about the future of fighting malware.

In order to ensure the safety of computer use, you must abide by the basic principles, pay attention to the content running on macOS devices, do not use risky pirated or cracked software for cheap, and be the first line of defense for your own information security. If you have a lot of highly confidential information on your work computer, you should be more cautious and not allow any application to record your screen.

◎Data source:MacRumors (1)、MacRumors (2)、Trend Micro

 

Source: KOCPC Chinese

Tags: appApp StoreMACmacOSmalwareTrojan horseVirusXcode

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology