EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack
ID: 799191ba-22ad-547c-8690-87554b84564f
STIX ID: report--799191ba-22ad-547c-8690-87554b84564f
Feed Name: cybersecurityNews.com
EmEditor’s official website was compromised for four days (Dec 19–22, 2025), distributing a maliciously modified installer (signed by a spoofed entity) that installed an advanced infostealer. The payload runs a VBScript that executes a PowerShell command to fetch code in memory, harvests credentials from multiple browsers and collaboration tools, and persists via a malicious browser extension with DGA and remote-control capabilities; users are advised to disconnect affected systems, scan, and reset credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
