logo

Hackers Hijacking Snap Domains to Posion Linux Software Packages for Desktops and Servers

ID: d53f67ea-5177-58d8-8938-ba00901a66dd

STIX ID: report--d53f67ea-5177-58d8-8938-ba00901a66dd

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-22

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Attackers are abusing the Canonical Snap Store by re-registering expired publisher domains, triggering password resets to take over established snap publisher accounts, and pushing malicious updates that install fake cryptocurrency wallet applications (masquerading as Exodus/Ledger Live) which harvest wallet recovery phrases in real time. Research by Alan Pope identified the coordinated campaign and specific compromised domains (storewise.tech, vagueentertainment.com); the report calls for Canonical to implement domain monitoring, enforce two‑factor authentication, and verify changes on dormant publisher accounts to mitigate the supply‑chain and account‑takeover threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.