logo

Trust Hijacked: Hackers Seize Expired Domains to Poison Linux Snap Apps

ID: 35c1fcc9-6326-5d30-a278-81e61dee345d

STIX ID: report--35c1fcc9-6326-5d30-a278-81e61dee345d

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: Ddos

...
...

A security advisory describes a campaign targeting the Canonical Snap Store where attackers register expired developer email domains, hijack the corresponding publisher accounts, and push malicious updates to otherwise-trusted Linux snaps. The tactic enables widespread automatic distribution of malware (notably to cryptocurrency wallet users) by exploiting lapsed domain registrations and weak account safeguards; the author urges domain maintenance and two-factor authentication and calls on Canonical to add protective controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.