London Daily

Focus on the big picture.
Sunday, Aug 02, 2026

Password manager Passwordstate hacked to deploy malware on customer systems

Password manager Passwordstate hacked to deploy malware on customer systems

A mysterious threat actor has compromised the update mechanism of enterprise password manager application Passwordstate and deployed malware on its users' devices, most of which are enterprise customers.

A mysterious threat actor has compromised the update mechanism of enterprise password manager application Passwordstate and deployed malware on its users’ devices, most of which are enterprise customers.

Click Studios, the Australian software firm behind Passwordstate, has notified its 29,000 customers earlier today via email.

According to a copy of the company’s communications, obtained by Polish tech news site Niebezpiecznik, the malware-laced update was live for 28 hours between April 20, 20:33 UTC and April 22, 00:30 UTC.


Danish security firm CSIS, which dealt with the aftermath of this supply chain attack, published today an analysis of the attacker’s malware. The security firm said the threat actor forced the Passwordstate apps to download an additional ZIP file named “Passwordstate_upgrade.zip” that contained a DLL file named “moserware.secretsplitter.dll.” After installation, this DLL file would ping a remote command and control server, from where it would request new commands and retrieve additional payloads.

While initially it was unknown what attackers collected from infected systems, in two updates [PDF, PDF] published after this article went live, Click Studios said the malware collected the following information and sent it back to its command and control server:

Computer Name, User Name, Domain Name, Current Process Name, Current Process Id, All running Processes name and ID, All running services name, Display name and status, Passwordstate instance’s Proxy Server Address, Username and Password

In other words, the password store was taken. According to the Australian company, the following information is typically included in the password table:

Title, UserName, Description, GenericField1, GenericField2, GenericField3, Notes, URL, Password

Although the company said “there is no evidence of encryption keys or database connection strings” were taken, Juan Andres Guerrero-Saade, Principal Threat Researcher at SentinelOne, pointed out on Twitter, that there are tools currently available that can decrypt the Passwordstate vaults and recover cleartext passwords.

Click Studios released a hotfix package [ZIP] that would help customers remove the attacker’s malware, which the company named Moserware. [instructions are in the image above]

Click Studios said the hack took place after a threat actor compromised the “In-Place Upgrade functionality” of a CDN network not controlled by Click Studios. Only the company’s Windows client appears to have been modified to add malware in the attack.

29,000 companies now have to rotate passwords


In the aftermath of this security breach, the Australian firm has told customers to change all the passwords they stored inside compromised Passwordstate password managers as soon as possible.

Since this is a password manager is sold primarily in bulk to enterprises, to whom it is advertised as an on-premises system, changing passwords won’t involve just email and website accounts, but also passwords for internal gear such as firewalls, VPNs, switches, routers, network gateways, and others, which many employees would most likely have saved inside the app thinking it was a secure local storage system.

“This is a real annoying breach,” William Thomas, a malware analyst at UK security firm Cyjax, told The Record. “Imagine having to change all your passwords for each device on the network, on a Friday.”

Several network administrators have told The Record on Friday that they had to work over the weekend to change the passwords of all their IT inventory as a result of the breach. Many companies also intend to activate incident response plans to check logs for unauthorized access as a result of this incident as well, resulting in many overtime hours for their already swamped security personnel.

Comments

Darth Neo 3 year ago
This is hardly relevant. The event happened in 2021 and the vendor identified and took action within 28hrs. They have subsequently made major improvements to their software, including removing the previous method of updating. The issue affected Build 9117 and they are now on release 9823. I have to question the reasoning on reporting news that is over 2 years old and has been resolved promptly by the vendor.

Newsletter

Related Articles

0:00
0:00
Close
Finland Deploys Commercial-Scale Thermal Batteries Using Crushed Rock to Store Renewable Grid Energy
Valued at $109 Million: F-35B Fighter Jet Crashes in Southern California
Sainsbury Agrees to Sell Argos in £120 Million Deal to Private Consortium
High Court Clears Way for Construction of Chinese Embassy at Royal Mint Court
UK Fuel Prices Climb to Multi-Month Highs as Strait of Hormuz Tensions Disrupt Oil Supplies
Severe Summer Drought and Record Heat Put UK Harvests at Risk
Prime Minister Andy Burnham Faces Labour Backbench Opposition Over Potential Support for New North Sea Oil and Gas Drilling
Bank of England Warns Inflation Will Stay Above 3% as Middle East Energy Shock Prolongs Cost-of-Living Pressures
Andy Burnham has Announces Plans to Redistribute Income Tax Revenue to English Mayors
Early-Release Scheme Faces Fresh Scrutiny as Reoffending and Prison Recalls Rise
Police Phone Checks Followed Report on Murder of MI5 Agent Inside Sinn Féin
Archbishop of Canterbury Reaffirms £100 Million Reparative Justice Fund During Ghana Visit
Charities Allege French Police Used Tear Gas Against Channel Migrants
Norwegian Teenager Convicted Over Iran-Linked Murder Plot in Britain
Christian Organisations File Charity Complaints Against Amnesty International UK
Ofgem Tightens Grid Connection Rules for New Data Centres
FTSE 100 Reaches Record High Despite Global Technology Sell-Off
Millions of UK Households Urged to Check Eligibility for Winter Energy Discount
Labour Restores Parliamentary Whips to Diane Abbott and Joani Reid
UK Supreme Court to Hear Challenge Over Palestine Action Ban
UK Commits More Than £8.4 Billion to Dreadnought Nuclear Submarine Programme
England Declares Severe Drought as Wildfire Burns Near Sizewell Nuclear Site
Bank of England Holds Interest Rates at 3.75% as Middle East Tensions Fuel Inflation Risks
Drought Status Extended Across All of Wales as Heat and Dry Weather Deepen Environmental Strain
Record-Low Danube Exposes Probable Mammoth Remains in Bulgaria
UK Business Confidence Climbs to Four-Month High
Greater Manchester Gains Expanded Powers Under Regional Funding Reforms
UK Supreme Court to Hear Appeal Over Palestine Action Terror Ban
Shell's Quarterly Profit Doubles to Nearly $10 Billion on Higher Energy Prices
UK Government Removes VAT From Household Electricity Bills
Exceptional Drought Grips Half of England as Wildfire Threatens Sizewell
Bank of England Holds Interest Rates at 3.75% as Inflation Risks Persist
US Says It Has Carried Out Heavy Strikes on Iran After Attempted Attacks on Its Forces
The chief executive of the popular gaming company laid off many employees and his pay rose to 38 million dollars
UK Employment Holds Steady as Wage Growth Remains Moderate
England to Introduce Artificial Intelligence into Secondary School Curriculum
Wales Launches £1.2 Billion Industrial Regeneration Programme
High Court Upholds UK Digital Surveillance Framework
Northern Ireland Reaches Budget Agreement on Infrastructure and Public Sector Pay
Home Office Expands Digital Border Checks Nationwide
UK Approves Major North Sea Wind and Carbon Capture Project
The World's Most Terrifying Smartphone: Recording, Documenting, and Reporting to the Regime
Scotland Approves Major Renewable Energy Expansion
UK and United States Sign AI and Semiconductor Cooperation Pact
UK Treasury Tightens Fiscal Controls After Gilt Market Volatility
Bank of England Holds Interest Rates at 4.5%
UK Unveils £10 Billion NHS Funding Overhaul and Workforce Reform
The AI User Nightmare: Private Claude Conversations Leaked to the Internet
UK: Former Football Association Leaders Call for World Cup Boycott Over FIFA Privatization Plan
Forbidden Love: China severs millions from their virtual partners
×