ChainCatcher reports that according to Chief Information Security Officer 23pds of SlowMist Technology, a new type of security vulnerability has appeared in the Snap Store application store on the Linux platform. Hackers hijack publisher accounts by taking over expired domain names and embed malicious code into cryptocurrency wallet applications.
Attackers monitor and register developer accounts associated with expired domains in the Snap Store, using these domain email addresses to trigger password resets, thereby taking over long-established trusted publisher identities. The tampered applications disguise themselves as well-known crypto wallets such as Exodus, Ledger Live, or Trust Wallet, with interfaces nearly indistinguishable from the genuine versions.
It has been confirmed that the publisher domains storewise[.]tech and vagueentertainment[.]com have been hijacked. These malicious applications trick users into entering “wallet recovery seed phrases.” Once submitted, sensitive information is transmitted to the attacker’s server, leading to theft of digital assets.