logo

Ubuntu 'command-not-found' tool can be abused to spread malware

ID: a8cb027a-73fa-5356-95b6-621435683beb

STIX ID: report--a8cb027a-73fa-5356-95b6-621435683beb

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-02-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Aqua Nautilus researchers discovered a logic flaw in Ubuntu's 'command-not-found' utility that can suggest malicious Snap packages to users (via typo-squatting, unclaimed snap names, or registering snaps that impersonate APT packages), creating a significant supply-chain and impersonation risk affecting Ubuntu, its forks, and WSL users; about 26% of APT commands are potentially exploitable and at least two malicious Snap incidents have been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.