Wire Observer.
Technology

New XCSSET Variant Leverages Chrome DevTools Protocol for Developer Supply Chain Attacks

New XCSSET Variant Leverages Chrome DevTools Protocol for Developer Supply Chain Attacks

A sophisticated malware campaign, identified as XCSSET v40, has re-emerged, specifically targeting macOS developers by embedding itself within legitimate Xcode projects. This latest iteration is designed to exploit the Chrome DevTools Protocol, enabling it to steal sensitive cookies and execute arbitrary commands on compromised systems, posing a significant risk of supply-chain compromise.

The threat actors behind XCSSET v40 have refined their distribution method, luring developers into downloading or cloning seemingly benign Xcode projects that have been secretly "poisoned." When a developer builds such a project locally, the malware activates, transforming their development environment into a potential launchpad for wider attacks.

A key innovation in XCSSET v40 is its abuse of the Chrome DevTools Protocol. This protocol is typically used by developers for debugging web applications, offering deep access to browser functions and data. XCSSET v40 subverts this legitimate tool, hijacking its capabilities to illicitly exfiltrate user cookies from the Chrome browser and run malicious commands directly on the developer's machine without their knowledge.

Once activated within a developer's system, XCSSET v40 possesses the ability to propagate further. It can spread to other Xcode projects on the compromised machine, escalating the initial breach into a broader threat landscape. This creates a ripple effect, where a single infected project can compromise an entire development workflow and potentially affect subsequent software releases.

The targeting of developers is particularly concerning due to their pivotal role in the software ecosystem. A breach at this level can have cascading consequences, potentially leading to compromised applications reaching end-users through legitimate distribution channels, hence the critical nature of a supply-chain attack.

This resurgence of XCSSET underscores the persistent and evolving nature of threats against the macOS platform and the developer community. As development tools become more interconnected and powerful, they also present new avenues for exploitation by sophisticated malware operations.

For macOS developers, the return of XCSSET v40 serves as a stark reminder of the importance of vetting all source code, even from seemingly trustworthy repositories, and maintaining robust security practices to safeguard their development environments against stealthy, project-embedded threats.

Christina Kyriasoglou — Bloomberg (Berlin, Germany)

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related