A critical alert has been issued for CVE-2026-63077, related to the XCSSET v40 malware targeting macOS developers. This version of the malware has resurfaced after months of dormancy, leveraging poisoned Xcode projects on GitHub to spread. Key features include browser hijacking, credential theft, and data exfiltration. The infection process involves an initial downloader script hidden in legitimate Xcode projects, executing once cloned by developers.
The malware employs sophisticated methods to conceal its operations, such as storing core logic in memory and utilizing separate encryption keys for command and control traffic. Defense strategies recommend behavior-based detection and careful scrutiny of software dependencies to mitigate risks.