EmEditor is a technology platform tracked across 2 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed December 29, 2025; most recent activity January 23, 2026.
EmEditor is a Windows text editor platform whose official website was compromised to deliver infostealer malware through a supply chain attack. The incident highlights how threat actors abuse legitimate software distribution channels and websites to disseminate malicious payloads, elevating credential and data theft risk for users.
EmEditor, a text and code editing tool, was compromised in a supply chain attack that led to the distribution of infostealer malware. The malicious installer was delivered through the official EmEditor website's…
In late December 2025, EmEditor, a widely used text and code editor, reported that its download page had been compromised. This incident involved a watering hole attack that aimed to distribute multistage malware…