discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Hola Browser for Windows compromised to deliver cryptominer

Hola Browser for Windows was hit by a supply-chain compromise that installed a hidden cryptominer on some systems. Hola says about 0.1% of users were affected.

By Bill Toulas·Jun 4·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Hola Browser for Windows compromised to deliver cryptominer
Image: bleepingcomputer.com

AppEsteem certification checks surfaced an undeclared Windows executable inside Hola Browser installs. Sophos identified it as a Monero miner that tried to evade detection, while Hola says it rebuilt its distribution pipeline after the compromise.

Why it matters

This is a supply-chain incident in software that users trust to download and update cleanly. It shows how a compromised distribution pipeline can turn a legitimate app into a malware delivery channel, even after certification checks had already been passed.

A browser maker’s delivery truck seems to have been sneaked into, and a hidden coin-mining program got put inside some Windows installs. It is like buying a toy box and finding a small machine inside that secretly uses the house’s electricity.

Analysis

What happened

BleepingComputer reports that the Windows version of Hola Browser was compromised in a supply-chain attack that delivered an undeclared executable. The issue was found during routine AppEsteem certification checks, after the browser had already passed earlier testing.

What the researchers found

According to the article, Sophos and other companies involved in the review found an unsigned, untimestamped file called me.exe under C:\Program Files\Hola\ in some installations. The binary contained obfuscated code, could write to memory, and included strings that pointed to a Monero miner. The malware reportedly added a Windows Defender exclusion, copied itself to HolaMonitorService.exe, created an auto-starting service named hola_monitor_svc, and ran when the system was idle.

Vendor response

Hola told AppEsteem that it had suffered a supply-chain compromise, which Sygnia also detected independently. The company says roughly 0.1% of users were affected and that there is no evidence of user data access, theft, or compromise. Hola’s CEO, Avi Raz Cohen, said the company rebuilt its distribution pipeline, added stronger code-signing checks, tightened access controls, and increased monitoring.

Security takeaway

The story is less about a browser bug than about trust in the software delivery chain. If an attacker can tamper with what gets shipped, a clean-looking app can become a malware installer without changing the user’s behavior.

Key points

  • Hola Browser for Windows was compromised in a supply-chain attack that delivered an undeclared executable.
  • Sophos identified the file as a Monero cryptominer based on its behavior and embedded strings.
  • The malicious component reportedly added a Defender exclusion, created an auto-starting service, and ran when the PC was idle.
  • Hola says about 0.1% of users were affected and there is no evidence of data theft or compromise.
  • The company says it rebuilt its distribution pipeline and tightened signing and monitoring controls.
The Upside

Hola says it rebuilt its distribution pipeline and added stricter signing checks, access controls, and monitoring. If those changes hold, future Windows releases should be harder to tamper with and easier to verify before they reach users.

The Downside

A supply-chain compromise means the attacker got close enough to the release process to ship a malicious component as if it were legitimate software. Even if only a small share of users were affected, incidents like this can undermine trust in updates and leave room for similar abuse on other platforms.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechsoftware-supply-chainmalwarecryptomining

Author

Bill Toulas

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 4, 2026

Source

bleepingcomputer.com

Share

Topics

securitytechsoftware-supply-chainmalwarecryptomining

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…