XCSSET Malware in xCode projects

Hi fews days ago when i open Safari it immediately open and close then open a fake Safari and see Fake Finder app in Application and after enable firewall i am not able to open safari and not able to other browser because this Malware taking cookies of all browser

So i did much research on it and finally got some temporary solution hope this can help you as well
  1. Reset Safari using terminal and delete support file from Library

  2. Check every project xcodeproj file using show package content and you can see a hidden file .xcassets in xcuserdata and delete that and also remove script in project name Build project framework you can see a script that runs this script

  3. Open xCode show package content and Resource> Scripts and delete main.script if you can see that file

  4. Delete Finder app in Application if it is created and also you can delete unknown app in System Preference > Security & Privacy > Privacy > Full Disk Access

In my case there was a Mail.app without icon

and now you are XCSSET free and not forgot to clear Caches and Clear Cookies from your Mac and restart
This is temporary solution from my research
Apple should take strict action for this Malware

Thank you,
Vivek Padaya

XCSSET Malware in xCode projects
 
 
Q