logo

Hackers Exploit Snap Domains to Inject Malicious Code into Linux Software Packages

ID: b7331877-11e6-5410-aef1-b862b271e5ee

STIX ID: report--b7331877-11e6-5410-aef1-b862b271e5ee

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-22

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A campaign is actively hijacking Snap Store publisher accounts by registering expired publisher domains, using password resets to take over established publisher accounts and push malicious revisions that act as cryptocurrency wallet stealers; the malware harvests recovery phrases and exfiltrates them (via Telegram bots), employing obfuscation (homoglyphs) and bait-and-switch publication techniques. The report documents C2 artefacts, sample Telegram identifiers, and recommends mitigations including domain expiry monitoring, mandatory 2FA, and stricter verification for account recovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.