EmEditor Website Breach Used to Spread Infostealer Malware
## Cybersecurity: EmEditor Supply Chain Attack Analysis
Cybersecurity: EmEditor Supply Chain Attack Analysis
Between December 19-22, 2025, EmEditor, a widely used text editor, encountered a sophisticated supply chain attack. The official website was compromised, distributing malware-laden installation packages.
Emurasoft, Inc., the developer, confirmed on December 23 that malicious MSI installers were provided via tampered download links. These installers bore fraudulent digital signatures from "WALSHAM INVESTMENTS LIMITED" instead of legitimate credentials.
The Qianxin Threat Intelligence Center's RedDrip Team identified this incident through its monitoring systems, capturing the entire malicious payload chain.
Given EmEditor's extensive user base among Chinese developers and technical professionals handling sensitive data, security researchers indicate the attack poses significant risks to government and enterprise institutions.
Sophisticated Multi-Stage Attack Chain
The compromised MSI installer (emed64_25.4.3.msi) included embedded malicious scripts executing PowerShell commands to disable system logging and deploy C# classes for data exfiltration.
The malware gathered system information, including OS version and usernames, encrypted the data with RSA encryption, and transmitted it to the command-and-control server at emeditorgb.com.
It targeted high-value directories such as Desktop, Documents, and Downloads, collecting file lists and packaging them into encrypted archives. The malware also extracted VPN configurations, Windows login credentials, and browser data from popular applications.
Between December 19-22, 2025, EmEditor, a widely used text editor, encountered a sophisticated supply chain attack.
Targeted software included enterprise collaboration platforms like Zoho Mail, Evernote, Notion, Discord, Slack, Mattermost, Microsoft Teams, and Zoom, along with secure file transfer tools such as WinSCP and PuTTY.
The malware captured screenshots and compressed all stolen data into a file named "array.bin" for exfiltration. It included geographic restrictions, terminating execution if it detected system languages associated with former Soviet countries or Iran.
A persistent browser extension, masquerading as "Google Drive Caching," was installed. This fully-featured infostealer communicated with cachingdrive.com and used Domain Generation Algorithm (DGA) logic to maintain operations.
The extension harvested comprehensive system metadata, captured browser history, cookies, installed extensions, bookmarks, and implemented clipboard hijacking functionality.
Additional capabilities included keylogging, Facebook advertising account theft, and remote control functions enabling operators to execute screenshots, read local files, establish proxy connections, and run arbitrary JavaScript code.
Qianxin's Tianqing "Liuhe" engine detects and blocks the malicious MSI installers . Deployment of this security engine is recommended for government and enterprise customers to defend against the threat.
Emurasoft confirmed that users who updated through EmEditor's built-in Update Checker or downloaded from download.emeditor.info directly remain unaffected.
The legitimate installer is signed by Emurasoft, Inc., with SHA-256 hash e5f9c1e9b586b59712cefa834b67f829ccbed183c6855040e6d42f0c0c3fcb3e, while the malicious version displays a file size of 80,380,416 bytes signed by WALSHAM INVESTMENTS LIMITED.
Organizations should isolate potentially affected systems, conduct comprehensive malware scans, and implement password resets with multi-factor authentication for exposed credentials.
Based on reporting by GBHackers.
