Hackers Infecting Apple App Developers With Trojanized Xcode Projects

enaph

Level 30
Thread author
Verified
Honorary Member
Top Poster
Well-known
Forum Veteran
Jun 14, 2011
1,843
2
12,358
2,879
Null Island
Cybersecurity researchers on Thursday disclosed a new attack wherein threat actors are leveraging Xcode as an attack vector to compromise Apple platform developers with a backdoor, adding to a growing trend that involves targeting developers and researchers with malicious attacks.

Dubbed "XcodeSpy," the trojanized Xcode project is a tainted version of a legitimate, open-source project available on GitHub called TabBarInteraction that's used by developers to animate iOS tab bars based on user interaction.

"XcodeSpy is a malicious Xcode project that installs a custom variant of the EggShell backdoor on the developer's macOS computer along with a persistence mechanism," SentinelOne researchers said.
 

You may also like...