Attackers compromised part of CPUID’s backend and briefly turned the official cpuid.com download flow into a malware delivery channel for trusted utilities including HWMonitor and CPU-Z. Reports indicate users who downloaded HWMonitor 1.63 or CPU-Z ZIP packages in early April received trojanized files, including an unexpected installer named HWiNFO_Monitor_Setup.exe. CPUID said a secondary feature or side API was breached for roughly six hours, while its signed software files and build pipeline were not compromised; affected links were later pulled and began returning 404 errors.
Analysis of the malicious samples found a multi-stage payload that dropped a fake CRYPTBASE.dll, contacted attacker-controlled infrastructure, and used PowerShell, in-memory execution, process injection, and on-host compilation of a .NET payload to evade detection and fetch follow-on malware. Researchers also observed behavior consistent with browser credential theft through Google Chrome’s IElevation COM interface, and reporting linked the infrastructure to earlier campaigns, including activity previously aimed at FileZilla users. The exact intrusion point remains unconfirmed, though scrutiny has focused on CPUID’s split download infrastructure involving download.cpuid.com and a Cloudflare R2 storage domain.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
By April 13, 2026, CPUID said the secondary API used in the website compromise had been fixed. The company also stated that legitimate direct download URLs and signed binaries were unaffected and that current downloads were safe.
By April 12, 2026, Kaspersky said the CPUID download-link compromise had infected more than 150 victims, mostly individuals but also organizations in retail, manufacturing, consulting, telecommunications, and agriculture. The company said most infections were observed in Brazil, Russia, and China.
By April 10, 2026, the malicious files had reportedly been pulled and affected download links were returning 404 errors. At that time, CPUID had not yet issued a full public statement in one report, while another cited the company's explanation that only a secondary backend component had been compromised.
On April 10, 2026, community reports and researcher analysis identified the malicious samples and described multi-stage behavior including PowerShell use, in-memory execution, process injection, and possible browser credential theft. Analysts also noted overlap between the attacker infrastructure and earlier malware campaigns, including activity linked to FileZilla-themed attacks.
Between April 9 and April 10, 2026, attackers briefly compromised a secondary CPUID backend feature or API and altered website download links to distribute malware. CPUID said its original signed software files and build pipeline were not breached.
Beginning in early April 2026, users downloading HWMonitor 1.63 and CPU-Z ZIP packages from CPUID infrastructure reportedly received malicious files instead of the expected software. The tampered downloads included a fake installer and malware components such as a rogue CRYPTBASE.dll that enabled staged payload delivery and command-and-control communication.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 106 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
9 references tracked. Mallory keeps watching after this page renders.
blog.alphahunt.io
Open sourcesecurityaffairs.com
Open sourcehelpnetsecurity.com
Open sourceghacks.net
Open sourcethehackernews.com
Open sourceintel.breakglass.tech
Open sourcecybersecuritynews.com
Open sourcegist.github.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.