Cemu Emulator Compromised with Malware in Linux Downloads

Cemu Emulator Compromised with Malware in Linux Downloads

First seen 13 May 2026, 18:12 UTC Gamingonlinuxrentry.org 73% similarity 71.0

Article Content

Browse articles
ThreatCluster

The Cemu emulator version 2.6 was compromised between May 6 and May 12, 2026, by a pro-Russian threat actor. The attack affected Linux users who downloaded the AppImage and Ubuntu zip files during this period. Windows and macOS users were not impacted, nor were those using Flatpak. The malware primarily aims to steal SSH keys, GitHub tokens, and passwords, potentially allowing further infections. A specific payload targets users in Israel, attempting to play a siren and wipe the filesystem. The compromised files have since been removed from GitHub, and users are advised to delete affected binaries and reset passwords. The developers are still investigating the full extent of the malware's capabilities.

Key Points: • Cemu 2.6 was compromised by a pro-Russian threat actor affecting Linux builds. • Malware targets SSH keys and GitHub tokens, facilitating further infections. • Users in Israel face an additional risk of filesystem wipe via a specific malware payload.

ThreatCluster AI

Timeline

2026-05-06
Malware introduced in Cemu 2.6 downloads
Compromised AppImage and Ubuntu zip files were uploaded to GitHub, affecting Linux users.
Gamingonlinux
2026-05-12
Compromise reported on GitHub
A ticket was opened on GitHub reporting the malware in Cemu builds, leading to immediate action by developers.
Gamingonlinux
2026-05-13
Developers remove compromised versions
Cemu developers confirmed the removal of the affected versions from GitHub and issued a security PSA.
rentry.org

Community

Browse all →