Supply chain Hola browser supply chain attack delivers cryptocurrency miner June 5, 2026 Share By SC Staff The Windows version of the Hola Browser has been compromised in a supply chain attack that delivered an undeclared executable identified as a cryptocurrency miner. This compromise was uncovered during periodic certification checks on Hola Browser as part of its AppEsteem certification testing procedure, according to a recent report by Bleeping Computer. Cybersecurity researchers at Sophos and other companies discovered an undeclared executable, identified as a Monero cryptocurrency miner, being installed with the Hola Browser. The file, named "me.exe", was not digitally signed, contained obfuscated code, and could write to memory. The miner installs itself as "HolaMonitorService.exe", creates an auto-starting Windows service, and runs when the computer is idle. Hola confirmed a supply chain compromise, stating that approximately 0.1% of its users were affected, with no evidence of user data access or theft. The company has since rebuilt its distribution pipeline and implemented enhanced security measures to prevent future incidents. Source: Bleeping Computer SC Staff Related Supply chain Why supply chain attacks work and what detection can actually do about it Aaron Beardslee June 2, 2026 Here’s what to do in a world where credential theft has been automated and turned into a commodity. Supply chain CISA adds Daemon Tools, TanStack, and Nx Console compromised versions to KEV catalog SC Staff May 29, 2026 The vulnerabilities include compromised versions of Daemon Tools Lite (CVE-2026-8398), TanStack npm packages (CVE-2026-45321), and the Nx Console extension (CVE-2026-48027) resulting from recent supply chain attacks. Supply chain New supply chain attack targets Laravel PHP packages with credential stealer SC Staff May 26, 2026 The attack compromises the release process of Laravel-Lang, affecting packages like laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Related Events Cybercast From code to cloud: Stopping attacks in the software supply chain On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds