Malware infiltrates Pidgin messenger’s official plugin repository
ID: 2e08dc64-2c2d-54bc-9aba-0c4a1143e83f
STIX ID: report--2e08dc64-2c2d-54bc-9aba-0c4a1143e83f
Feed Name: Bleeping Computer
A malicious third-party Pidgin plugin named 'ss-otr' was discovered and removed after it was found to contain a keylogger and functionality to download additional payloads, including DarkGate malware, for both Windows and Linux. The installer was signed with a valid certificate issued to a legitimate company, and the same attacker-controlled server hosted multiple other malicious plugins, indicating a broader campaign; Pidgin has pulled the plugin and will now only accept OSI-approved open-source licensed plugins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
