Security Researchers Discover XcodeSpy Malware That Targets Developers

Developers need to look out for "XcodeSpy," a malicious Xcode project that installs a custom variant of the "EggShell" backdoor on a macOS computer, according to new research shared today by SentinelOne (via Ars Technica).

iu 2 1
Xcode is software designed for developers who want to write apps for the iOS and macOS platforms, and the malicious project that's circulating mirrors TabBarInteraction, a legitimate open source project.

Developers who download the XcodeSpy project think they're getting TabBarInteraction, but the malware includes a hidden "run Script" executable that downloads and installs the EggShell open source back door that's able to spy on users through the microphone, camera, and keyboard as well as upload and download files.

Two variants of the custom EggShell attack were found to be uploaded in Japan, first in August and then in October, so this is an attack that's been out in the wild for some time.

We have thus far been unable to discover other samples of trojanized Xcode projects and cannot gauge the extent of this activity. However, the timeline from known samples and other indicators mentioned below suggest that other XcodeSpy projects may exist. By sharing details of this campaign, we hope to raise awareness of this attack vector and highlight the fact that developers are high-value targets for attackers.

SentinelOne says that all Apple Developers that use Xcode should exercise caution when using shared Xcode projects.

Tag: Xcode

Popular Stories

Generic iOS 18

iOS 18.1 With Apple Intelligence: New Features, Release Date, and More

Thursday October 10, 2024 8:26 am PDT by
iOS 18.1 will be released to the public in the coming weeks, and the software update introduces the first Apple Intelligence features for the iPhone. Below, we outline when to expect iOS 18.1 to be released. iOS 18.1: Apple Intelligence Features Here are some of the key Apple Intelligence features in the iOS 18.1 beta so far: A few Siri enhancements, including improved understanding...
top stories 12oct2024

Top Stories: iOS 18.1 Release Date, New Macs Incoming, and More

Saturday October 12, 2024 6:00 am PDT by
Things are firming up for a big Halloween week for Apple, with the company's next operating system updates reportedly coming early in the week and hardware launches coming a few days later. Ahead of those hardware launches, we've recently seen what appears to be one of the most significant physical product leaks in years, while some of the new features in Apple's recent software updates have ...
16 pro

iPhone 17 Pro Models Rumored to Introduce These 5 New Features

Friday October 11, 2024 8:55 am PDT by
While the iPhone 16 series was released just a few weeks ago, there are already many rumored features for the iPhone 17 models, and especially for the Pro models. Below, we recap five key new features rumored for the iPhone 17 Pro and Pro Max so far: 24MP front camera for all iPhone 17 models: All four iPhone 17 models will feature an upgraded 24-megapixel front-facing camera, according...
maxresdefault

The MacRumors Show: Apple's Shocking M4 MacBook Pro Leak

Friday October 11, 2024 8:27 am PDT by
On this week's episode of The MacRumors Show, we discuss the unprecedented leak of Apple's M4 MacBook Pro models and the company's rumored move to more staggered hardware and software releases. Subscribe to The MacRumors Show YouTube channel for more videos Multiple leaks surrounding Apple's unannounced 14-inch MacBook Pro with the M4 chip recently surfaced online. The leaks began with unboxin...
ios 18 1 make primary

iOS 18.1 Includes Option to Set 'Primary' Email Address and Change iCloud Email

Friday October 11, 2024 3:55 pm PDT by
In iOS 18.1, there is a new option to set a "Primary" email address in the Settings app, which means it is easier to change the main email address associated with your Apple Account. The Primary email address is the one that is visible to other people when collaborating on and sharing documents, sending calendar invites, and more. Apple did not previously make it easy to change an Apple...
Generic iOS 18 Feature Real Mock

Apple Stops Signing iOS 18.0

Thursday October 10, 2024 12:10 pm PDT by
Apple today stopped signing iOS 18.0, preventing iPhone users who have upgraded to iOS 18.0.1 from downgrading to iOS 18. Apple released iOS 18.0.1 a week ago on October 3. It is not unusual for Apple to stop signing older versions of iOS within a week or two after a new version of iOS is released. When Apple stops signing an update, it can no longer be installed on an iPhone due to a...
iPad mini review thumb

iPad Mini 7 Coming Next Month: What to Expect

Tuesday October 8, 2024 6:16 am PDT by
Rumors strongly suggest Apple will release the seventh-generation iPad mini in November, nearly three years after the last refresh. Here's a roundup of what we're expecting from the next version of Apple's small form factor tablet, based on the latest rumors and reports. Design and Display The new iPad mini is likely to retain its compact 8.3-inch display and overall design introduced with...
When Will Apple Launch More M4 Macs Feature

Will Apple Release M4 Macs Soon? Here's What the Latest Rumors Say

Thursday October 10, 2024 6:22 am PDT by
Apple often releases new Macs in the fall, but we are still waiting for official confirmation that the company has similar plans this year. We're approaching the middle of October now, and if Apple plans to announce new Macs before the holidays, recent history suggests it will happen this month. Here's what we know so far. As of writing this, it's been 220 days since Apple released a new...
space black mbp

Apple Potentially Facing Worst Leak Since iPhone 4 Was Left in a Bar

Monday October 7, 2024 3:03 pm PDT by
Alleged photos and videos of an unannounced 14-inch MacBook Pro with an M4 chip continue to surface on social media, in what could be the worst product leak for Apple since an employee accidentally left an iPhone 4 prototype at a bar in California in 2010. The latest video of what could be a next-generation MacBook Pro was shared on YouTube Shorts today by Russian channel Romancev768, just...

Top Rated Comments

jonnysods Avatar
47 months ago
Get ready for lots of Justin Long Intel videos about this next week.
Score: 9 Votes (Like | Disagree)
Apple_Robert Avatar
47 months ago

Laughing on my Linux developer laptop.
What is so funny? It's not like Linux hasn't had Malware problems.
Score: 7 Votes (Like | Disagree)
I7guy Avatar
47 months ago
Comes under the heading, be very careful about what you download.
Score: 6 Votes (Like | Disagree)
hot-gril Avatar
47 months ago

Why is it being called a Trojan when it has to be actively installed?
Cause that's what trojans are.
Score: 5 Votes (Like | Disagree)
hot-gril Avatar
47 months ago

Comes under the heading, be very careful about what you download.
Xcode does warn you when opening an xcodeproj downloaded from the Internet, but given how frequently you legitimately have to open and build random projects, I wish there were better sandboxing. The "run script" phase runs arbitrary code, ofc necessary when building many things but also an attack vector.

Edit: And even if you're not manually opening/building projects, you're probably using Cocoapods, which is. Of course other dev platforms have similar risks.
Score: 4 Votes (Like | Disagree)
Unsupported Avatar
47 months ago

Why is it being called a Trojan when it has to be actively installed?
https://usa.kaspersky.com/resource-center/threats/trojans

A Trojan horse or Trojan is a type of malware that is often disguised as legitimate software. Trojans can be employed by cyber-thieves and hackers trying to gain access to users' systems. Users are typically tricked by some form of social engineering into loading and executing Trojans on their systems. Once activated, Trojans can enable cyber-criminals to spy on you, steal your sensitive data, and gain backdoor access to your system. These actions can include:

•Deleting data
•Blocking data
•Modifying data
•Copying data
•Disrupting the performance of computers or computer networks


Modifying data?

So it could infect the project that the developer is working on?

Nasty!
Score: 3 Votes (Like | Disagree)