Unofficial repositories for Kodi, an open-source media player, are distributing add-ons that lead to the download of cryptomining malware for Windows and Linux platforms.

This operation appears to have started in December 2017 via the “script.module.simplejson” add-on hosted by the now-closed Bubbles repository. When Bubbles was shut down, the Gaia repository continued to distribute the malicious add-on.
Security researchers from ESET detected the same add-on in the XvBMC repository, which was recently shut down for copyright infringement, but it is very likely that other repositories are also distributing the malicious file.
The five countries affected are the United States, Israel, Greece, the United Kingdom, and the Netherlands, which is also the country of origin of the XvBMC repository. These countries are also the same ones that see the most traffic for Kodi add-ons.
Currently, 'script.module.simplejson' is at version 3.4.0, while the malicious repositories are distributing version 3.4.1. Since the repositories have the higher version, Kodi users automatically install the malicious file.
“The code is clearly written by someone with good knowledge of Kodi’s architecture and add-ons. The script detects the operating system it is running (only Windows and Linux are supported), connects to its server, and then downloads and executes a module appropriate for that operating system,” the researchers note.
Users' systems can become infected when searching for updates in a malicious repository or when they install a version of Kodi with pre-installed hardware that includes the add-on's URL.
ESET estimates that users who installed a third-party repository with Kodi are at risk of being infected with cryptomining malware.
