ELSEIF
Your brief EB
541 stories from 214 feeds 1271 clusters Refreshed 36 minutes ago next pull 21:39

SECURITY Signal 56

XCSSET malware found in pub.dev Flutter package example files, not library code

Aikido Security detected XCSSET malware inside the example directory of universal_file_viewer version 0.1.5 on pub.dev, marking the first compromised package found on the Dart and Flutter registry.

WHY IT MATTERS

The malware only exists in example build files that are never compiled when the package is used as a dependency, so most consumers are unaffected. However, developers who clone the repository and build the example app locally on macOS would be infected, and XCSSET's worm modules would then propagate to all Gradle, Xcode, and git projects on their machine.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

XCSSET malware was found in the example directory of universal_file_viewer version 0.1.5 on pub.dev, the first compromised package detected on the registry.

02

The infection came from the maintainer's compromised machine rather than a deliberate supply chain attack, and the library code itself remains clean.

03

XCSSET is a macOS worm that propagates by injecting malicious build hooks into Android Gradle projects, Xcode projects, and git repositories, and includes persistence and data theft modules.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Aikido Security's Blog Compromised Flutter package on pub.dev contains XCSSET malware Open ↗