The team behind Pale Moon announced yesterday that its archive server was hacked. Hackers breached the server of the Pale Moon browser project and infected older versions of the browser with malware.
According to the announcement, published by the lead developer, MC Straver, the attack had been going on for 18 months, but was discovered now.
The “archive server” essentially hosts older versions of the browser. The developers want to have older versions available in case any of the users want to abandon the current stable version and revert to an earlier one.
According to Straver, a malicious group had gained access to the archive server (archive.palemoon.org). After gaining access, the hackers ran a malicious script that selectively infected all Pale Moon .exe files stored on the server. To infect the files, the hackers used a variant of Win32/ClipBanker.DY (ESET).
The Pale Moon browser development team was notified of the security the day before yesterday, July 9, and immediately removed the compromised archive server.

The attack took place in 2017.
After investigation, it was discovered that the breach had occurred on December 27, 2017 at approximately 3:30 PM.
"It is possible that these dates and times are fake, but considering the backups taken from the archives, it is likely that this is the actual date and time of the breach."
Straver said that all versions prior to Pale Moon 27.6.2 have been infected with the malware. Oddly enough, older versions of the Basilisk web browser were not affected, despite being hosted on the same server.
Unfortunately, the Pale Moon team was unable to detect the breach in May, when the archive server encountered some problems.
They target cryptocurrencies users
Pale Moon developers advise users who have downloaded files from the archive server to scan their systems.
The Win32/ClipBanker.DY trojan infects systems and monitors the operating system's clipboard. This particular variant monitors Bitcoin addresses. Through this, hackers can transfer victims' funds to their own addresses.
