Hola Browser for Windows compromised to deliver cryptominer
The Windows version of Hola Browser was compromised in a supply chain attack that delivered an undeclared cryptocurrency miner executable to users. The compromise affected the browser's distribution or update mechanism.
- Disclosed
- Last updated
- Blast radius
- Windows users of Hola Browser
- Ecosystems
- Attack vectors
- Affected entities
- Hola BrowserWindows version compromised to deliver cryptominer
The Windows version of Hola Browser was compromised in a supply chain attack that resulted in the delivery of malicious code to end users. Researchers identified an undeclared executable embedded in the compromised browser distribution that functioned as a cryptocurrency miner.
The attack represents a direct compromise of the browser's distribution or update infrastructure, allowing attackers to inject malicious payloads into legitimate software downloads. Users who installed or updated the affected Windows version of Hola Browser would have received the cryptominer without their knowledge or consent.
This incident demonstrates the risk of supply chain compromise at the application level, where attackers gain control over software distribution channels to deliver secondary payloads to a broad user base.
Indicators of compromise
- Packages
- Hola Browser
Remediation
- Uninstall Hola Browser for Windows immediately
- Scan systems for cryptocurrency miner processes and artifacts
- Monitor system resources for unusual CPU usage or network activity indicative of cryptomining
- Update to a patched version of Hola Browser once available from official sources
- Consider using alternative browsers from trusted vendors
Sources
- Hola Browser for Windows compromised to deliver cryptominer · BleepingComputer
Cite this entry
"Hola Browser for Windows compromised to deliver cryptominer." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 4, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/hola-browser-for-windows-compromised-to-deliver-cryptominer-1smv3g
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activehigh
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Russian threat actor UAT-11795 is distributing trojanized versions of WebEx and Zoom applications to deploy Starland RAT malware for credential theft and cryptocurrency theft. The campaign targets users of these widely-used communication platforms.
OtherCompromised package - containedhigh
M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
M-Red-Team compromised AsyncAPI npm packages via GitHub Actions, injecting malicious code into the supply chain. The attack leveraged build system access to distribute compromised packages to downstream consumers.
M Red TeamnpmOtherCompromised packageBuild-system compromise - activehigh
New ChocoPoC malware targets researchers via trojanized PoC exploits
Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering ChocoPoC, a Python-based remote access trojan (RAT) capable of executing commands and stealing sensitive data. The campaign is believed to target cybersecurity researchers.
OtherMalicious commitCompromised package - containedcritical
Malware in setup-cicd
The npm package setup-cicd was found to contain malware, potentially giving outside entities full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmOtherCompromised package