Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
vendor-distribution-compromisebuild-pipeline-compromiseoffensive-tooling-release

Supply Chain Compromise Delivered XMRig-Like Miner via Hola Browser

Updated 11d agoFirst seen Jun 4, 20266 sources

Sophos X-Ops reported that Hola Browser version 1.251.91.0 was distributed with an undeclared executable, me.exe, discovered during an AppEsteem Windows Certified Application validation test. The file was absent from the certified component list and showed multiple suspicious characteristics, including no code signing, no timestamp, obfuscated code, memory-write capability, and behavior consistent with a cryptocurrency miner. Sophos said the preserved sample appeared to be an XMRig-based miner and detects it as Troj/GoMiner-B.

Hola said its update distribution pipeline suffered a supply chain compromise that affected about 0.1% of users, adding that it found no evidence of user data access or exfiltration. Sophos assessed the issue was more likely caused by delivery-path or pipeline variance than by a malicious fixed installer payload, and escalated the case through AppEsteem. Hola and AppEsteem said the affected delivery pipeline was halted and rebuilt, while stronger code-signing verification, tighter access controls, continuous monitoring, and a forensic investigation supported by Sygnia were put in place.

Share:
Supply Chain Compromise Delivered XMRig-Like Miner via Hola Browser
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jun 5, 202614d ago

New miner behaviors disclosed in Hola compromise analysis

Further analysis of the me.exe payload found it established persistence as the Windows service hola_monitor_svc, ran when systems were idle, and tried to evade detection by adding a Windows Defender exclusion. These details expanded the known technical behavior of the XMRig-based miner delivered through the compromised Hola Browser pipeline.

Hola Browser for Windows Delivery Pipeline Compromised to Deliver Cryptominer - Cyber Security News
Jun 4, 202616d ago

Sophos identifies preserved sample as XMRig-based miner

Sophos identified the preserved me.exe sample as an apparent XMRig-based miner and detects it as Troj/GoMiner-B. This provided technical characterization of the suspicious executable delivered with Hola Browser.

You do surprise me.exe: An unexpected executable in Hola Browser | SOPHOS

Hola and AppEsteem halt and rebuild affected delivery pipeline

According to Hola and AppEsteem, the affected delivery pipeline was halted and rebuilt following the compromise. They also implemented stronger code-signing verification, tighter access controls, and continuous monitoring.

You do surprise me.exe: An unexpected executable in Hola Browser | SOPHOS

Hola discloses supply chain compromise in update distribution pipeline

Hola stated that its update distribution pipeline had suffered a supply chain compromise affecting 0.1% of users. The company said no user data was accessed or exfiltrated and that it had engaged Sygnia to support the forensic investigation.

You do surprise me.exe: An unexpected executable in Hola Browser | SOPHOS

Sophos escalates Hola Browser finding through AppEsteem

After analyzing the unexpected executable, Sophos concluded the issue likely resulted from delivery-path or pipeline variance rather than a fixed installer payload. Sophos then escalated the matter through AppEsteem for further handling.

You do surprise me.exe: An unexpected executable in Hola Browser | SOPHOS

Sophos finds undeclared me.exe in Hola Browser validation test

During an AppEsteem Windows Certified Application validation test, Sophos X-Ops discovered an undeclared executable named me.exe being delivered alongside Hola Browser version 1.251.91.0. Sophos found the file suspicious because it was absent from the certified component list and showed traits including no code signing, no timestamp, obfuscated code, memory-write capability, and behavior consistent with a crypto-miner.

You do surprise me.exe: An unexpected executable in Hola Browser | SOPHOS
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Affected products
4 linked
WindowsWindows DefenderMicrosoft DefenderChromium
Organizations
5 linked
HolaSophosAppEsteemSygniaBleepingComputer
Breaches
1 linked
HOLA-2026-06
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.