Malware & Threats

New XCSSET macOS Malware Variant Hijacks Cryptocurrency Transactions

The malware now uses a four-stage infection chain, has an additional persistence mechanism, and also targets Firefox browser data.

macOS malware

An updated variant of the sophisticated XCSSET macOS malware is monitoring the system clipboard to hijack cryptocurrency transactions, Microsoft warns.

First observed in the wild half a decade ago, XCSSET spreads via malicious Xcode projects, abusing Apple’s integrated development environment for macOS.

The malware was designed to steal information from various chat applications, steal files, inject code in websites, and drop ransom notes, and has received several updates over time.

The most recent variant, Microsoft says, includes an additional persistence mechanism and brings changes to browser targeting and clipboard hijacking.

The threat employs a four-stage infection chain, with changes to its boot function, which now includes additional checks for Firefox and a modified check for Telegram.

At the fourth stage of the chain, the malware fetches a run-only compiled AppleScript that defines functions related to data validation, encryption, decryption, and for obtaining additional data from the command-and-control (C&C) server.

Advertisement. Scroll to continue reading.

The script also contains functions associated with clipboard monitoring, which allows it to identify cryptocurrency addresses and replace them with content defined in a list of attacker-controlled addresses.

The malware was also seen fetching from the C&C another script with file exfiltration capabilities, and setting up LaunchDaemon persistence by creating a file containing the payload in the user’s home directory.

It was also seen modifying system configurations to execute commands that disabled the macOS security configuration updates and Rapid Security Response mechanism.

XCSSET also creates a fake system settings application and then calls a function that waits for the legitimate System Settings application to be launched before executing the fake app, to pose as legitimate.

The new malware variant also includes an info-stealer module targeting the Firefox browser. A modified version of the HackBrowserData open source project, the module steals browser history, cookies, and stored passwords and credit card information.

Microsoft reported its findings to Apple and worked with GitHub to remove the malicious repositories distributing the malware.

“While we’re only seeing this new XCSSET variant in limited attacks as of this writing, we’re publishing our comprehensive analysis to increase awareness of this evolving threat,” the company notes.

Related: PyPI Warns Users of Fresh Phishing Campaign

Related: Widespread Infostealer Campaign Targeting macOS Users

Related: Microsoft Warns of Improved XCSSET macOS Malware

Related: North Korean Hackers Target macOS Users

Related Content

Malware & Threats

Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Cybercrime

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.

Artificial Intelligence

The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.

Artificial Intelligence

Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints.

Malware & Threats

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.

Malware & Threats

The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.

Malware & Threats

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version