Hola Browser Compromised to Deliver Cryptominer via Supply Chain Attack

Hola Browser Compromised to Deliver Cryptominer via Supply Chain Attack

First seen 4 Jun 2026, 19:37 UTC News.SophosBlogs.SophosBleepingcomputerGbhackersScworld+1 87% similarity 67.5

Article Content

Browse articles
ThreatCluster

The Hola Browser for Windows (version 1.251.91.0) was compromised in a supply chain attack, delivering an undeclared executable identified as a cryptocurrency miner. This issue was discovered during AppEsteem certification checks, which revealed the presence of the executable 'me.exe' in some installations. The binary lacked code signing, a timestamp, and contained obfuscated code, indicating malicious intent. Hola confirmed the compromise, stating that only 0.1% of users were affected and that no user data was accessed or stolen. The company has since rebuilt its distribution pipeline and implemented advanced security measures. The incident highlights significant vulnerabilities in software supply chains and the importance of rigorous application integrity checks.

Key Points: • Hola Browser was compromised to deliver a crypto-miner via supply chain attack. • The malicious executable 'me.exe' was not part of the certified application footprint. • Hola has implemented new security measures to prevent future incidents.

ThreatCluster AI

Timeline

2026-06-04
Compromise discovered during certification checks
Sophos X-Ops identified an undeclared executable 'me.exe' in Hola Browser during AppEsteem tests.
News.Sophos
2026-06-04
Hola confirms supply chain compromise
Hola acknowledged the delivery of the malicious executable and stated that only 0.1% of users were affected.
BleepingComputer
2026-06-05
Hola implements new security measures
Following the incident, Hola has rebuilt its distribution pipeline and enhanced security protocols.
Gbhackers

Community

Browse all →