logo

Malware infiltrates Pidgin messenger’s official plugin repository

ID: 2e08dc64-2c2d-54bc-9aba-0c4a1143e83f

STIX ID: report--2e08dc64-2c2d-54bc-9aba-0c4a1143e83f

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-08-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A malicious third-party Pidgin plugin named 'ss-otr' was discovered and removed after it was found to contain a keylogger and functionality to download additional payloads, including DarkGate malware, for both Windows and Linux. The installer was signed with a valid certificate issued to a legitimate company, and the same attacker-controlled server hosted multiple other malicious plugins, indicating a broader campaign; Pidgin has pulled the plugin and will now only accept OSI-approved open-source licensed plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.