Hola Browser for Windows compromised to deliver cryptominer
Hola Browser for Windows was hit by a supply-chain compromise that installed a hidden cryptominer on some systems. Hola says about 0.1% of users were affected.
Intelligence analysis by GPT-5.4 Mini

AppEsteem certification checks surfaced an undeclared Windows executable inside Hola Browser installs. Sophos identified it as a Monero miner that tried to evade detection, while Hola says it rebuilt its distribution pipeline after the compromise.
A browser maker’s delivery truck seems to have been sneaked into, and a hidden coin-mining program got put inside some Windows installs. It is like buying a toy box and finding a small machine inside that secretly uses the house’s electricity.
Analysis
What happened
BleepingComputer reports that the Windows version of Hola Browser was compromised in a supply-chain attack that delivered an undeclared executable. The issue was found during routine AppEsteem certification checks, after the browser had already passed earlier testing.
What the researchers found
According to the article, Sophos and other companies involved in the review found an unsigned, untimestamped file called me.exe under C:\Program Files\Hola\ in some installations. The binary contained obfuscated code, could write to memory, and included strings that pointed to a Monero miner. The malware reportedly added a Windows Defender exclusion, copied itself to HolaMonitorService.exe, created an auto-starting service named hola_monitor_svc, and ran when the system was idle.
Vendor response
Hola told AppEsteem that it had suffered a supply-chain compromise, which Sygnia also detected independently. The company says roughly 0.1% of users were affected and that there is no evidence of user data access, theft, or compromise. Hola’s CEO, Avi Raz Cohen, said the company rebuilt its distribution pipeline, added stronger code-signing checks, tightened access controls, and increased monitoring.
Security takeaway
The story is less about a browser bug than about trust in the software delivery chain. If an attacker can tamper with what gets shipped, a clean-looking app can become a malware installer without changing the user’s behavior.
Key points
- Hola Browser for Windows was compromised in a supply-chain attack that delivered an undeclared executable.
- Sophos identified the file as a Monero cryptominer based on its behavior and embedded strings.
- The malicious component reportedly added a Defender exclusion, created an auto-starting service, and ran when the PC was idle.
- Hola says about 0.1% of users were affected and there is no evidence of data theft or compromise.
- The company says it rebuilt its distribution pipeline and tightened signing and monitoring controls.
Hola says it rebuilt its distribution pipeline and added stricter signing checks, access controls, and monitoring. If those changes hold, future Windows releases should be harder to tamper with and easier to verify before they reach users.
A supply-chain compromise means the attacker got close enough to the release process to ship a malicious component as if it were legitimate software. Even if only a small share of users were affected, incidents like this can undermine trust in updates and leave room for similar abuse on other platforms.



