Hackers Hijacking Snap Domains to Posion Linux Software Packages for Desktops and Servers
ID: d53f67ea-5177-58d8-8938-ba00901a66dd
STIX ID: report--d53f67ea-5177-58d8-8938-ba00901a66dd
Feed Name: cybersecurityNews.com
Attackers are abusing the Canonical Snap Store by re-registering expired publisher domains, triggering password resets to take over established snap publisher accounts, and pushing malicious updates that install fake cryptocurrency wallet applications (masquerading as Exodus/Ledger Live) which harvest wallet recovery phrases in real time. Research by Alan Pope identified the coordinated campaign and specific compromised domains (storewise.tech, vagueentertainment.com); the report calls for Canonical to implement domain monitoring, enforce two‑factor authentication, and verify changes on dormant publisher accounts to mitigate the supply‑chain and account‑takeover threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
