Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0658
MITRE ATT&CK Malware

XCSSET (S0658)

OSX.DubRobber
ShareXLinkedInRedditHN

[XCSSET](https://attack.mitre.org/software/S0658) is a modular macOS malware family delivered through infected Xcode projects and executed when the project is compiled. Active since August 2020, it has been observed installing backdoors, spoofed browsers, collecting data, and encrypting user files. It is composed of SHC-compiled shell scripts and run-only AppleScripts, often hiding in apps that mimic system tools (such as Xcode, Mail, or Notes) or use familiar icons (like Launchpad) to avoid detection.(Citation: trendmicro xcsset xcode project 2020)(Citation: April 2021 TrendMicro XCSSET)(Citation: Microsoft March 2025 XCSSET)

Platforms: macOS

▪Techniques implemented (33)

T1564.001Hidden Files and DirectoriesT1518Software DiscoveryT1614.001System Language DiscoveryT1105Ingress Tool TransferT1041Exfiltration Over C2 ChannelT1553.001Gatekeeper BypassT1036MasqueradingT1195.001Compromise Software Dependencies and Development ToolsT1098.004SSH Authorized KeysT1005Data from Local SystemT1573.001Symmetric CryptographyT1574.006Dynamic Linker HijackingT1560Archive Collected DataT1548.006TCC ManipulationT1222.002Linux and Mac PermissionsT1539Steal Web Session CookieT1056.002GUI Input CaptureT1068Exploitation for Privilege EscalationT1569.001LaunchctlT1518.001Security Software DiscoveryT1486Data Encrypted for ImpactT1082System Information DiscoveryT1543.004Launch DaemonT1647Plist File ModificationT1027.013Encrypted/Encoded FileT1083File and Directory DiscoveryT1059.004Unix ShellT1497.003Time Based ChecksT1554Compromise Host Software BinaryT1087Account DiscoveryT1546Event Triggered ExecutionT1113Screen CaptureT1546.004Unix Shell Configuration Modification
S0658on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.