HomeSecurityEmEditor Editor hacked to distribute infostealer

EmEditor Editor hacked to distribute infostealer

A major supply chain attack targeting EmEditor, a widely used word processor, exposed millions of users to sophisticated infostealer malware.

See also: “Sryxen” malware manages to bypass Chrome encryption

EmEditor

From December 19 to 22, 2025, the official EmEditor website underwent an unauthorized modification, resulting in users receiving infected installation files instead of legitimate programs during these critical four days.

The company confirmed that users who downloaded version 25.4.3 via the “Download Now” button received malicious files instead of the legitimate software, creating a significant security breach that affected developers, system administrators, and technical professionals around the world. The attack exploited the redirect mechanism that controls the download path of EmEditor. The attackers modified the URL settings that normally direct users to the legitimate installation files, sending them instead to a malicious version hosted in EmEditor’s WordPress content directory.

See also: Battlefield 6: Fake versions distribute infostealer

EmEditor Editor hacked to distribute infostealer

The infected installer was digitally signed by "WALSHAM INVESTMENTS LIMITED", an unofficial organization, instead of by Emurasoft Inc., the legitimate creator of the software.

This misleading signature added a false level of authenticity that many users might not have questioned.

Qianxin analysts identified the malware after careful forensic analysis, revealing a full package of infostealing functionality embedded in the installation file.

The malicious code featured a sophisticated design that mimics the legitimate functionality of EmEditor, allowing it to operate silently during and after installation, collecting sensitive user data.

See also: LeakyInjector and LeakyStealer steal cryptocurrencies and browsing history

EmEditor Editor hacked to distribute infostealer

Victims are advised to immediately disconnect affected systems, perform full malware scans, and reset all passwords used on infected devices.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS