Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedhigh

Hola Browser for Windows compromised to deliver cryptominer

The Windows version of Hola Browser was compromised in a supply chain attack that delivered an undeclared cryptocurrency miner executable to users. The compromise affected the browser's distribution or update mechanism.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Windows users of Hola Browser
Ecosystems
Attack vectors
Affected entities
  • Hola BrowserWindows version compromised to deliver cryptominer

The Windows version of Hola Browser was compromised in a supply chain attack that resulted in the delivery of malicious code to end users. Researchers identified an undeclared executable embedded in the compromised browser distribution that functioned as a cryptocurrency miner.

The attack represents a direct compromise of the browser's distribution or update infrastructure, allowing attackers to inject malicious payloads into legitimate software downloads. Users who installed or updated the affected Windows version of Hola Browser would have received the cryptominer without their knowledge or consent.

This incident demonstrates the risk of supply chain compromise at the application level, where attackers gain control over software distribution channels to deliver secondary payloads to a broad user base.

Indicators of compromise

Packages
  • Hola Browser

Remediation

  • Uninstall Hola Browser for Windows immediately
  • Scan systems for cryptocurrency miner processes and artifacts
  • Monitor system resources for unusual CPU usage or network activity indicative of cryptomining
  • Update to a patched version of Hola Browser once available from official sources
  • Consider using alternative browsers from trusted vendors

Sources

  1. Hola Browser for Windows compromised to deliver cryptominer · BleepingComputer

Cite this entry

"Hola Browser for Windows compromised to deliver cryptominer." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 4, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/hola-browser-for-windows-compromised-to-deliver-cryptominer-1smv3g

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activehigh

    Russian hackers trojanize WebEx, Zoom apps to push Starland malware

    Russian threat actor UAT-11795 is distributing trojanized versions of WebEx and Zoom applications to deploy Starland RAT malware for credential theft and cryptocurrency theft. The campaign targets users of these widely-used communication platforms.

    OtherCompromised package
  2. containedhigh

    M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions

    M-Red-Team compromised AsyncAPI npm packages via GitHub Actions, injecting malicious code into the supply chain. The attack leveraged build system access to distribute compromised packages to downstream consumers.

    M Red TeamnpmOtherCompromised packageBuild-system compromise
  3. activehigh

    New ChocoPoC malware targets researchers via trojanized PoC exploits

    Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering ChocoPoC, a Python-based remote access trojan (RAT) capable of executing commands and stealing sensitive data. The campaign is believed to target cybersecurity researchers.

    OtherMalicious commitCompromised package
  4. containedcritical

    Malware in setup-cicd

    The npm package setup-cicd was found to contain malware, potentially giving outside entities full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmOtherCompromised package