CPUID, the developer of CPU-Z and HWMonitor, confirmed that attackers compromised a backend website component and used a secondary API to replace legitimate download links with malware-laced installers for roughly six hours. The company said its signed software, source code, and build infrastructure were not breached, but the website intermittently served malicious files to users downloading or updating the Windows utilities. Reports from users and researchers, backed by VirusTotal detections, showed the poisoned downloads were delivered from CPUID’s trusted site, making the incident a software supply-chain attack.
Analysis shared by researchers indicated the trojanized packages used a malicious CRYPTBASE.dll side-load technique, with payloads linked to an Alien RAT variant that executed much of its activity in memory via PowerShell, contacted command-and-control infrastructure, and attempted to steal browser credentials and session data from Chrome through the IElevation COM interface. Researchers also noted similarities to infrastructure seen in earlier campaigns targeting FileZilla users. CPUID took its site offline, removed the malicious links, fixed the abused API, and restored clean downloads, while users who downloaded CPU-Z or HWMonitor during the affected window were urged to assume compromise, reinstall Windows or otherwise thoroughly clean systems, log out of active sessions, and change passwords.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
Following disclosure of the incident, security experts advised anyone who downloaded CPU-Z or HWMonitor on April 9 or April 10 to treat their systems as compromised. Recommended actions included reinstalling Windows or otherwise cleaning infected systems, logging out of active sessions, and changing passwords.
Security researchers observed similarities between the infrastructure used in the CPUID incident and an earlier 2026 campaign targeting FileZilla users. This suggested the compromise may have been part of a broader credential-stealing operation.
Analysis shared by vx-underground found the malicious installer used a fake Zig-compiled CRYPTBASE.dll, executed much of its activity in memory via PowerShell, contacted command-and-control infrastructure, and attempted to steal browser credentials through Chrome-related mechanisms. Reporting identified the payload as an Alien RAT variant focused on passwords and session tokens.
CPUID stated that attackers abused a compromised backend component or secondary API to swap legitimate download links with malicious ones. The company temporarily took its website offline, removed the malicious links, and later restored clean download routing after fixing the issue.
During the incident, users and security researchers reported on X and Reddit that CPUID downloads were infected, and VirusTotal detections indicated the installers contained trojanized malware. These reports helped surface the compromise publicly.
Between April 9 and April 10, CPUID's website was compromised and randomly displayed malicious links for CPU-Z and HWMonitor downloads, affecting both direct downloads and some in-app updates. CPUID said its signed software files, source code, and build process were not compromised.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
neowin.net
Open sourcecyberwarzone.com
Open sourcecybernews.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.