Kaspersky reported that the official cpuid.com website was used in a watering hole attack that affected downloads of the popular Windows utilities CPU-Z and HWMonitor. The incident exposed users seeking legitimate system information and hardware monitoring tools to malicious content delivered through the trusted software distribution channel, turning the vendor’s own site into the point of compromise.
The attack highlights the risk of software supply-chain abuse through legitimate download portals, particularly for widely used administrative and diagnostic tools. Organizations that allow CPU-Z or HWMonitor in enterprise environments should verify whether any copies were obtained from the compromised site, review affected hosts for signs of unauthorized payload execution, and prioritize integrity checks, endpoint telemetry review, and reinstallation from a known-clean source once vendor remediation is confirmed.

Trace attribution and downstream blast radius.
1 event from the most recent confirmed update back to the earliest known activity.
Securelist published a report about a watering hole attack involving CPU-Z, HWMonitor, and cpuid.com. No additional incident details or earlier dated events are provided in the reference metadata.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 38 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.