Flutter Pavilion — State 01 ![]()
When Flutter developers choose a new package, we usually ask familiar questions:
-
Does it have good pub points?
-
Is it actively maintained?
-
How many downloads does it have?
-
Does the source code look reasonable?
Those are good questions, but a security incident discovered in September 2026 added another question in mind:
What else is actually inside this package?
On September 8, 2026, Aikido Security reported finding a variant of XCSSET malware inside version 0.1.5 of the Flutter package universal_file_viewer on pub.dev, while at the time of reporting, the package already had 500 downloads ..
What makes this case particularly interesting is that the package’s main Dart library was apparently not malicious at all! ..
A Clean lib/ Directory Wasn’t Enough
According to Aikido’s analysis report, the Dart code inside: lib/ was clean, the infected files were instead in:example/
When developers add a Flutter package normally through pubspec.yaml, the example project is not compiled as part of their application, so simply writing:universal_file_viewer: ^0.1.5and running a normal Flutter build did not automatically trigger the malware! ..
The dangerous scenario was different this time!
A developer had to clone the repository and explicitly build the included example application locally for the malicious code to be activated ..
So, What Was XCSSET Doing There?
XCSSET is a macOS-focused malware family known for targeting software developers and, specially, Xcode projects ..
Microsoft has documented XCSSET variants that infect Xcode projects and execute malicious code when developers build those projects. The malware has also evolved with techniques for persistence, obfuscation, data theft, and propagation between development projects [Read the full technical analysis in the Microsoft Security Blog on XCSSET] ..
In the Flutter package investigated by Aikido, several development configurations inside the example project had been modified, with Aikido reporting infections involving:example/android/app/build.gradle.ktsas well as the example application’s iOS and macOS Xcode project configurations ..
For instance, Flutter may gave us a single cross-platform development experience, but inside a Flutter application we still have native ecosystems:
Android + iOS + macOS + Xcode + Git .. and more
It Wasn’t Necessarily a Malicious Package Author
There is another important part of this story. According to Aikido’s investigation, this was not believed to be a case where someone deliberately created a malicious Flutter package and uploaded it to pub.dev. Instead, the maintainer’s development machine was reportedly already infected with XCSSET.
The malware then modified development files on that machine, that when a new version of the package was published, those infected files were packaged and distributed with that new version ..
Build Systems Are Code Too
Anything capable of executing instructions deserves security attention, regardless of whether the filename ends in
.dart..
Our machines often contain many repositories, credentials, package-manager tokens, Git access, signing configurations, API keys, and development tools, meaning that a compromised developer environment can therefore be extremely valuable to an attacker ..
What Should Flutter Developers Do?
This incident doesn’t mean developers should stop using packages, Flutter’s package ecosystem is one of the reasons we can build applications so efficiently ..
The better lesson is to become a little more intentional about what we bring into our projects, before adopting an unfamiliar package, take a few minutes to inspect more than its README file, look at the repository structure, check recent releases, look at the publisher, inspect unusual native files, pay attention to unexpected build scripts or hooks, and check what changed between versions ..
What Happened to the Package?
The current pub.dev listing shows versions 0.1.5 and 0.1.6 as retracted, for more information check here [pub.dev universal_file_viewer Versions Page] ..
On version 0.1.7 lists a security update stating that unauthorized Xcode build rules and script phases were removed from the example iOS and macOS project configurations ..
Trust is useful, but verification is better ..
This is my Flutter Pavilion
: A small series exploring Flutter, Dart, development practices, and the cybersecurity lessons that matters ..
flutter dart #CyberSecurity #AppSecurity #OpenSourceSecurity