logo

EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack

ID: 799191ba-22ad-547c-8690-87554b84564f

STIX ID: report--799191ba-22ad-547c-8690-87554b84564f

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-30

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

EmEditor’s official website was compromised for four days (Dec 19–22, 2025), distributing a maliciously modified installer (signed by a spoofed entity) that installed an advanced infostealer. The payload runs a VBScript that executes a PowerShell command to fetch code in memory, harvests credentials from multiple browsers and collaboration tools, and persists via a malicious browser extension with DGA and remote-control capabilities; users are advised to disconnect affected systems, scan, and reset credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.