SECURITY Signal 56
XCSSET malware found in pub.dev Flutter package example files, not library code
Aikido Security detected XCSSET malware inside the example directory of universal_file_viewer version 0.1.5 on pub.dev, marking the first compromised package found on the Dart and Flutter registry.
The malware only exists in example build files that are never compiled when the package is used as a dependency, so most consumers are unaffected. However, developers who clone the repository and build the example app locally on macOS would be infected, and XCSSET's worm modules would then propagate to all Gradle, Xcode, and git projects on their machine.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
XCSSET malware was found in the example directory of universal_file_viewer version 0.1.5 on pub.dev, the first compromised package detected on the registry.
The infection came from the maintainer's compromised machine rather than a deliberate supply chain attack, and the library code itself remains clean.
XCSSET is a macOS worm that propagates by injecting malicious build hooks into Android Gradle projects, Xcode projects, and git repositories, and includes persistence and data theft modules.
THE CLUSTER
↗