Arab Press

بالشعب و للشعب
Tuesday, Jul 21, 2026

Password manager Passwordstate hacked to deploy malware on customer systems

Password manager Passwordstate hacked to deploy malware on customer systems

A mysterious threat actor has compromised the update mechanism of enterprise password manager application Passwordstate and deployed malware on its users' devices, most of which are enterprise customers.

A mysterious threat actor has compromised the update mechanism of enterprise password manager application Passwordstate and deployed malware on its users’ devices, most of which are enterprise customers.

Click Studios, the Australian software firm behind Passwordstate, has notified its 29,000 customers earlier today via email.

According to a copy of the company’s communications, obtained by Polish tech news site Niebezpiecznik, the malware-laced update was live for 28 hours between April 20, 20:33 UTC and April 22, 00:30 UTC.


Danish security firm CSIS, which dealt with the aftermath of this supply chain attack, published today an analysis of the attacker’s malware. The security firm said the threat actor forced the Passwordstate apps to download an additional ZIP file named “Passwordstate_upgrade.zip” that contained a DLL file named “moserware.secretsplitter.dll.” After installation, this DLL file would ping a remote command and control server, from where it would request new commands and retrieve additional payloads.

While initially it was unknown what attackers collected from infected systems, in two updates [PDF, PDF] published after this article went live, Click Studios said the malware collected the following information and sent it back to its command and control server:

Computer Name, User Name, Domain Name, Current Process Name, Current Process Id, All running Processes name and ID, All running services name, Display name and status, Passwordstate instance’s Proxy Server Address, Username and Password

In other words, the password store was taken. According to the Australian company, the following information is typically included in the password table:

Title, UserName, Description, GenericField1, GenericField2, GenericField3, Notes, URL, Password

Although the company said “there is no evidence of encryption keys or database connection strings” were taken, Juan Andres Guerrero-Saade, Principal Threat Researcher at SentinelOne, pointed out on Twitter, that there are tools currently available that can decrypt the Passwordstate vaults and recover cleartext passwords.

Click Studios released a hotfix package [ZIP] that would help customers remove the attacker’s malware, which the company named Moserware. [instructions are in the image above]

Click Studios said the hack took place after a threat actor compromised the “In-Place Upgrade functionality” of a CDN network not controlled by Click Studios. Only the company’s Windows client appears to have been modified to add malware in the attack.

29,000 companies now have to rotate passwords


In the aftermath of this security breach, the Australian firm has told customers to change all the passwords they stored inside compromised Passwordstate password managers as soon as possible.

Since this is a password manager is sold primarily in bulk to enterprises, to whom it is advertised as an on-premises system, changing passwords won’t involve just email and website accounts, but also passwords for internal gear such as firewalls, VPNs, switches, routers, network gateways, and others, which many employees would most likely have saved inside the app thinking it was a secure local storage system.

“This is a real annoying breach,” William Thomas, a malware analyst at UK security firm Cyjax, told The Record. “Imagine having to change all your passwords for each device on the network, on a Friday.”

Several network administrators have told The Record on Friday that they had to work over the weekend to change the passwords of all their IT inventory as a result of the breach. Many companies also intend to activate incident response plans to check logs for unauthorized access as a result of this incident as well, resulting in many overtime hours for their already swamped security personnel.

Comments

Darth Neo 3 year ago
This is hardly relevant. The event happened in 2021 and the vendor identified and took action within 28hrs. They have subsequently made major improvements to their software, including removing the previous method of updating. The issue affected Build 9117 and they are now on release 9823. I have to question the reasoning on reporting news that is over 2 years old and has been resolved promptly by the vendor.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
High Prices Push Coffee Drinkers Toward Whole Beans and Home Brewing
Trump Draws Boos and Podium Scrutiny at Spain’s World Cup Triumph
Spain Defeats Argentina in Extra Time to Win Second World Cup
Turkey Explores S-400 Transfer to UAE in Bid to Rejoin F-35 Program
US Retaliates Against Iran After Two American Troops Killed in Jordan
Proposed U.S.-Saudi Nuclear Pact Could Permit Limited Uranium Enrichment Under International Safeguards
Why Kentucky Fried Chicken Became KFC—and Why the False Explanations Persist
Iran Claims It Destroyed Bahrain’s Main Artificial Intelligence Center in Missile and Drone Strike
Ukrainian Drones Strike Wildberries Warehouses Deep Inside Russia
Reported CIA Mission Helped Clear the UAE’s Path to Advanced US AI Chips
Artificial Intelligence Capital Fuels Markets While Governments and Regulators Face Mounting Strategic Tests
China’s Moonshot’s Kimi K3 Narrows the Gap With Anthropic Through Scale, Openness and Lower Cost
The Ledger Will Not Trust on Faith
Passenger Bound for Germany Refused to Sit Beside a Woman on a Plane — Then Slapped a Flight Attendant
Ukraine’s Leadership Rift Spills Into the Streets as Protesters Target Army Chief
The Ten World Cup Finals That Defined Football History
Smartphones Are Getting More Expensive, Sales Are Collapsing, and Even Apple Admits: "Prices Will Rise"
Leadership Change and Strategic Rivalry Redraw the Political Map
The AI Race Enters Its Infrastructure Era
Britain Nationalises British Steel to Protect Scunthorpe Production and Strategic Supply
Thomas Tuchel Faces Fierce Backlash After Tactical Retreat Costs England World Cup Final Berth
A Quiet Bastille Day: France Grapples with World Cup Heartbreak and Leftover Fireworks
Spain in Ecstasy: "We Feel Unbeatable, We Taught the Whole World a Lesson"
Harvard Astrophysicist to Lead U.S. Scientific Advisory on Unidentified Aerial Phenomena
Emergency Sirens Activated Across Bahrain as Interior Ministry Issues Shelter Directives
World Cup Visitors Turn American Big-Box Stores Into Souvenir Stops
Netflix Weighs Always-On Channels, Bundles and Short-Form Video
The AI Invoice Shock: Layoffs Didn't Save Managers Money — They Cost Them More
Concern: Sexually Transmitted Bacterium Among Men Develops Antibiotic Resistance
Passenger Partially Pulled Out of Ryanair Jet After Cabin Window Fails Mid-Flight
Severe Heatwave Drives Dangerous Ground-Level Ozone Pollution Across Two Thirds of European Union
The Physical and Electronic Barriers Disrupting Domestic Wireless Networks
France and Morocco Open World Cup Quarter-Finals as Collina Defends Refereeing
Tech Pulse: The Future of AI and Screen Culture
Global News Briefing: Escalating Geopolitical Tensions and Corporate Shakeups
Global News Brief: Escalating Conflicts, Public Health Crises, and World Cup Drama
Europe's Growing Struggle with Extreme Heat and Air Conditioning
Anthropic Reengineers Agentic Architecture to Shift Autonomous Workplace Automation to the Cloud
Logic Flaw in Windows 11 Permission Architecture Silently Consumes Hundreds of Gigabytes of Local Storage
Apple Advances Late-Stage Operating Systems with Fourth Beta Deployments
Global Crisis Alert: Escalating Middle East Tensions and UK Political Upheaval
Japanese Technology Firm Fujitsu Launches Advanced Artificial Intelligence Tool for Corporate Disclosures
South Africa Officially Launches Nationwide Campaign for Highly Contested Local Government Elections
United Kingdom Commits Additional Funding for Unexploded Ordnance Clearance in Laos
Singapore Announces Stringent New Greenhouse Gas Regulations for Commercial Cooling Systems
Cambodia and Thailand Hold High-Level Border Security Talks at United Nations Headquarters
Myanmar Military Government and China Sign Major Agreement to Upgrade Media and Cultural Cooperation
Knife Attack at Swiss Train Station Leaves Three Injured in Suspected Act of Domestic Terrorism
Transnational Extortion Gang Threatens Canadian Police With Army of One Thousand Armed Operatives
Australia Imposes Forty-Two-Day Quarantine on Cruise Ship Passengers Following Deadly Hantavirus Outbreak
×