Linux users were targeted with crypto-stealing malware delivered through the Canonical Snap Store after attackers hijacked legitimate Snap publisher accounts by registering expired domains tied to dormant developers. According to warnings from Ubuntu contributor and former Canonical developer Alan Pope, once an attacker controls a lapsed domain and its email, they can reset credentials for the associated Snap/Snapcraft publisher account and push malicious updates to previously trustworthy applications—turning auto-updates into a silent distribution channel.
The activity follows earlier Snap Store abuse patterns (fake wallet apps, filter evasion with lookalike characters, and “bait-and-switch” snaps that later update into wallet stealers), but the domain-takeover method undermines a key trust signal: established publisher history. Pope cited at least two cases involving domains storewise.tech and vagueentertainment.com, where malicious snaps were used to harvest crypto wallet recovery phrases and exfiltrate them to attacker-controlled servers. Canonical reportedly removed the identified malicious snaps, while Pope advised heightened caution—especially around cryptocurrency wallet applications—and highlighted the risk posed by abandoned projects whose domains lapse.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
In the wake of the disclosures, Pope and subsequent reporting urged Canonical to add safeguards including domain-expiry monitoring, stronger verification for dormant publisher accounts, and mandatory two-factor authentication. Users were also advised to obtain wallet apps from official project sites rather than app stores when possible.
Following reporting on the malicious updates, Canonical removed the identified compromised snaps from the Snap Store. Pope noted, however, that takedown of reported malicious snaps can sometimes take days.
Ubuntu contributor and Anchore's Alan Pope documented the activity, identifying at least two compromised publisher domains, storewise.tech and vagueentertainment.com, and describing the domain-hijack technique as a significant escalation in Snap Store abuse. He also linked the malicious infrastructure to regions near Croatia in one report.
After taking over publisher accounts, the attackers published trojanized Snap packages impersonating cryptocurrency wallets such as Exodus, Ledger Live, and Trust Wallet. The malicious apps harvested wallet recovery phrases, exfiltrated them to attacker-controlled servers, and in some cases victims reportedly lost up to $490,000.
Attackers began registering expired domains formerly used by legitimate but inactive Snap Store publishers, then used control of those domains and email infrastructure to reset credentials and take over trusted Snapcraft accounts. This domain-takeover method enabled compromise of existing publisher identities rather than creation of new fake accounts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.