logo

Inside the EmEditor supply chain compromise

ID: f1e92311-879f-5d63-b156-e30d84c3d5e9

STIX ID: report--f1e92311-879f-5d63-b156-e30d84c3d5e9

Feed Name: ReversingLabs Blog

Threat Score
85/100

Date Published: 2026-01-29

Date Updated: 2026-04-29

Author: Robert Simmons

...
...

This technical investigation analyzes the December 2025 EmEditor software supply-chain compromise, detailing how adversaries modified MSI installers (overwriting installer actions and embedding VBScript/PowerShell stagers), exposed deterministic forensic artifacts in MSI SummaryInformation, and operated reusable C2 infrastructure; the report provides hashes, domains, IPs, URLs, timeline analysis, and mitigation recommendations for early domain monitoring and build/package integrity controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.