CryptoMediaClub
Tuesday, June 2, 2026
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
CryptoMediaClub
No Result
View All Result
Home All news

Hackers Hijack Snap Store Accounts to Push Crypto-Stealing Malware on Linux

21.01.2026
A A
0
121
VIEWS
ShareShare

Cryptocurrency hackers are exploiting trusted Linux software to steal digital assets, using a new technique that turns legitimate Snap Store packages into malware.

Key Takeaways:

  • Hackers are exploiting trusted Snap Store packages to steal cryptocurrency by hijacking existing publisher accounts.
  • The attacks rely on expired domains and email addresses to push malicious updates.
  • The incidents reveal weaknesses in the platform’s trust and security model.

Rather than creating fresh accounts on the Snap Store, which is operated by Canonical, attackers are now taking over existing publisher accounts, according to a warning from Ubuntu contributor and former Canonical developer Alan Pope.

The method relies on identifying expired web domains and email addresses linked to long-standing Snap Store developers, registering those domains, and then using the recovered access to hijack Snapcraft accounts.

Attackers Turn Legitimate Packages Malicious

Once inside, the attackers push malicious updates to packages that were previously benign, catching users off guard through automatic updates and long-established trust signals.

The Snap Store, like other major package repositories, has long been a target for malware campaigns.

Early efforts were relatively unsophisticated, with scammers publishing fake crypto wallet applications under newly created accounts.

When those attempts became easier to detect, attackers began disguising malicious apps using lookalike characters from other alphabets to evade filters.

According to Pope, the tactic then evolved into a bait-and-switch approach. Attackers would publish harmless software under neutral names such as “lemon-throw” or “alpha-hub,” often posing as simple games. After approval and a period of inactivity, a follow-up update would quietly introduce a fake crypto wallet designed to steal funds.

The latest development raises the stakes. In at least two confirmed cases, attackers took control of expired domains once owned by legitimate Snap publishers and used them to distribute wallet-stealing malware through automatic updates.

A new Snap Store scam campaign abuses expired publisher domains to bypass trust signals and deliver malicious app updates.https://t.co/nWL9HGXACe#Linux #OpenSource

— Linuxiac (@linuxiac) January 19, 2026

The affected applications appeared normal on the surface but were built to harvest wallet recovery phrases and transmit them to attacker-controlled servers.

By the time users noticed suspicious behavior, funds and sensitive data were already compromised.

Canonical has since removed the malicious snaps, but Pope warned that the response highlights deeper weaknesses in the platform’s trust model.

He said domain takeovers undermine publisher longevity as a safety signal and called for additional safeguards, including monitoring domain expirations, enforcing stronger account verification for dormant publishers, and requiring mandatory two-factor authentication.

Security Researcher Warns of Delayed Snap Store Takedowns

Pope also noted delays in removing reported malicious snaps, sometimes stretching over several days.

He advised users to exercise extra caution when installing cryptocurrency wallets on Linux and to consider downloading them directly from official project websites instead of app stores.

To help users assess risk, Pope created SnapScope, a web-based tool that flags snaps as suspicious or malicious before installation.

He also urged developers to keep domain registrations active and secure Snapcraft and email accounts with two-factor authentication.

According to Chainalysis, illicit cryptocurrency addresses received a record $154 billion in 2025, a sharp increase from the year before.

In another case, US prosecutors have charged a 23-year-old Brooklyn resident, Ronald Spektor, with stealing roughly $16 million in cryptocurrency from around 100 Coinbase users through an alleged phishing and social engineering scheme.

The post Hackers Hijack Snap Store Accounts to Push Crypto-Stealing Malware on Linux appeared first on Cryptonews.

Share9Tweet6ShareSharePin2

Related Posts

Ethereum ETFs Bled $708m in 14 Straight Days as XRP and Solana Gained
All news

Ethereum ETFs Bled $708m in 14 Straight Days as XRP and Solana Gained

02.06.2026
0

Ethereum’s market dominance is retreating toward critical support as the sell-the-news phase following U.S. spot Ethereum ETF approvals transitions into...

Read moreDetails
Bitcoin Layer-2 Scaling Solution Bitcoin Hyper Surpasses $32.7 Million in Presale Funding

Bitcoin Layer-2 Scaling Solution Bitcoin Hyper Surpasses $32.7 Million in Presale Funding

01.06.2026
Sam Altman ChatGPT AI Predicts Incredible XRP Price By End of June 2026

Sam Altman ChatGPT AI Predicts Incredible XRP Price By End of June 2026

01.06.2026
Bitcoin Slumps to $71,500 as Geopolitical Tensions Trigger $400M+ in Liquidations

Bitcoin Slumps to $71,500 as Geopolitical Tensions Trigger $400M+ in Liquidations

01.06.2026
Senator Lummis Warned That Stalling the CLARITY Act Now Means No Crypto Regulation Until 2030

Senator Lummis Warned That Stalling the CLARITY Act Now Means No Crypto Regulation Until 2030

01.06.2026
Load More
Next Post
Ethereum Price Prediction: NYSE-Listed Company Just Added $100M in ETH – Are Institutions Quietly Loading Up?

Ethereum Price Prediction: NYSE-Listed Company Just Added $100M in ETH – Are Institutions Quietly Loading Up?

0 0 votes
Рейтинг статьи
Subscribe
Notify of
guest
guest
0 комментариев
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recommended

Blockchain key to verifying authenticity of real-world media — Nodle

Blockchain key to verifying authenticity of real-world media — Nodle

3 years ago
Profit-taking, not capitulation: institutions cut Bitcoin ETF exposure by 23% in Q1

Profit-taking, not capitulation: institutions cut Bitcoin ETF exposure by 23% in Q1

12 months ago
Bitcoin is trapped in a $54 billion Nvidia gamble that could trigger a sudden institutional sell-off

Bitcoin is trapped in a $54 billion Nvidia gamble that could trigger a sudden institutional sell-off

5 months ago
Sam Altman ChatGPT AI Predicts Shock XRP Price By End of 2026

Sam Altman ChatGPT AI Predicts Shock XRP Price By End of 2026

2 weeks ago

Categories

  • All news
  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
No Result
View All Result

Highlights

Bitcoin Layer-2 Scaling Solution Bitcoin Hyper Surpasses $32.7 Million in Presale Funding

Cardano just canceled is 2026 Summit – exposing the power and risk of its governance vetos

Sam Altman ChatGPT AI Predicts Incredible XRP Price By End of June 2026

Bitcoin Slumps to $71,500 as Geopolitical Tensions Trigger $400M+ in Liquidations

A mystery whale paid $30 million to exit BlackRock Bitcoin ETF before the market fell

Senator Lummis Warned That Stalling the CLARITY Act Now Means No Crypto Regulation Until 2030

Trending

Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself
Analysis

Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself

02.06.2026
0

A white-hat researcher's recovery of 1,003.62 ETH from a failed 2016 Ethereum ICO has turned an old...

Ethereum ETFs Bled $708m in 14 Straight Days as XRP and Solana Gained

Ethereum ETFs Bled $708m in 14 Straight Days as XRP and Solana Gained

02.06.2026
XRP’s 15-week low puts ETF inflows to the spot-market test

XRP’s 15-week low puts ETF inflows to the spot-market test

01.06.2026
Bitcoin Layer-2 Scaling Solution Bitcoin Hyper Surpasses $32.7 Million in Presale Funding

Bitcoin Layer-2 Scaling Solution Bitcoin Hyper Surpasses $32.7 Million in Presale Funding

01.06.2026
Cardano just canceled is 2026 Summit – exposing the power and risk of its governance vetos

Cardano just canceled is 2026 Summit – exposing the power and risk of its governance vetos

01.06.2026
  • All news
  • Altcoins
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
  • Analysis
Editor: cryptomediaclub.com@gmail.com
Advertising: digestmediaholding@gmail.com

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

wpDiscuz