ChainCatcher reports that according to Chief Information Security Officer 23pds of SlowMist Technology, a new type of security vulnerability has appeared in the Snap Store application store on the Linux platform. Hackers hijack publisher accounts by taking over expired domain names and embed malicious code into cryptocurrency wallet applications.
Attackers monitor and register developer accounts associated with expired domains in the Snap Store, using these domain email addresses to trigger password resets, thereby taking over long-established trusted publisher identities. The tampered applications disguise themselves as well-known crypto wallets such as Exodus, Ledger Live, or Trust Wallet, with interfaces nearly indistinguishable from the genuine versions.
It has been confirmed that the publisher domains storewise[.]tech and vagueentertainment[.]com have been hijacked. These malicious applications trick users into entering “wallet recovery seed phrases.” Once submitted, sensitive information is transmitted to the attacker’s server, leading to theft of digital assets.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Snap Store security vulnerability allows hackers to steal users' crypto assets by hijacking expired domains
ChainCatcher reports that according to Chief Information Security Officer 23pds of SlowMist Technology, a new type of security vulnerability has appeared in the Snap Store application store on the Linux platform. Hackers hijack publisher accounts by taking over expired domain names and embed malicious code into cryptocurrency wallet applications.
Attackers monitor and register developer accounts associated with expired domains in the Snap Store, using these domain email addresses to trigger password resets, thereby taking over long-established trusted publisher identities. The tampered applications disguise themselves as well-known crypto wallets such as Exodus, Ledger Live, or Trust Wallet, with interfaces nearly indistinguishable from the genuine versions.
It has been confirmed that the publisher domains storewise[.]tech and vagueentertainment[.]com have been hijacked. These malicious applications trick users into entering “wallet recovery seed phrases.” Once submitted, sensitive information is transmitted to the attacker’s server, leading to theft of digital assets.