# Passwordstate COMPROMISED

**URL:** https://cog.discourse.group/t/passwordstate-compromised/1858
**Category:** george
**Created:** [April 26, 2021, 11:45am UTC](https://cog.discourse.group/t/passwordstate-compromised/1858 "2021-04-26T11:45:12Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Ook](https://sea1.discourse-cdn.com/flex001/user_avatar/cog.discourse.group/ook/32/72_2.png) [@Ook](https://cog.discourse.group/u/Ook)
#### Post date: [April 26, 2021, 11:45am UTC](https://cog.discourse.group/t/passwordstate-compromised/1858/1 "2021-04-26T11:45:12Z")

</div>

> [@](#):
>
> As many as 29,000 users of the Passwordstate password manager downloaded a malicious update that extracted data from the app and sent it to an attacker-controlled server, the app-maker told customers.
> 
> In an [email](https://twitter.com/niebezpiecznik/status/1385563976004681730/photo/1), Passwordstate creator [Click Studios](https://www.clickstudios.com.au/about-us.aspx) told customers that bad actors compromised its upgrade mechanism and used it to install a malicious file on user computers. The file, named “moserware.secretsplitter.dll,” contained a legitimate copy of an app called [SecretSplitter](https://github.com/moserware/SecretSplitter), along with malicious code named “Loader,” according to a [brief writeup](https://www.csis.dk/newsroom-blog-overview/2021/moserpass-supply-chain/) from security firm CSIS Group.

Link to the [story (Ars Technicia)](https://arstechnica.com/gadgets/2021/04/hackers-backdoor-corporate-password-manager-and-steal-customer-data/).

---

<div class="post-metadata">

### Author: ![RRabbit42](https://sea1.discourse-cdn.com/flex001/user_avatar/cog.discourse.group/rrabbit42/32/79_2.png) [@RRabbit42](https://cog.discourse.group/u/RRabbit42)
#### Post date: [April 26, 2021, 1:53pm UTC](https://cog.discourse.group/t/passwordstate-compromised/1858/2 "2021-04-26T13:53:24Z")

</div>

As mentioned in the article, that’s the same process used in the SolarWinds breach. Wikipedia has info about their FTP server having an easy password (“solarwinds123”) in 2019 and employee passwords were stored on GitHub back then, too. Based on what happened next, the FTP password wasn’t changed after it was reported to them as a risk.

NPR has two reports on SolarWinds. The [first](https://www.npr.org/2021/04/20/989015617/the-solarwinds-attack-the-story-behind-the-hack) is shorter and you can either listen to it or read the transcript. The [second](https://www.npr.org/2021/04/16/988178153/the-story-behind-the-solarwinds-cyberattack) is 14 minutes long without a transcript. I heard most of it on Friday driving home. The key point is a simple test file was uploaded to see if it could be done and then they disappeared for five months. That gave them time to work on the full attack program and scrub the code of any identifiers like comments.

So a file name like “moserware.secretsplitter.dll” would stand out if anyone was simply scanning through a list of file names and the first thing I thought of was “Does ‘moserware’ or ‘secretsplitter’ have anything to do with Passwordstate?” I don’t know if it does but Click Studios should for their own product.
