from Hacker News

KeePass trojanised in advanced malware campaign

by melicerte on 5/12/25, 12:40 PM with 2 comments

  • by Ukv on 5/12/25, 1:11 PM

    > signed version of the open-source password manager KeePass [...] KeePass’s actual source code was altered [...] risks of trusted software being hijacked

    To be clear, as far as I'm able to tell from the report, the actual KeePass is safe and has not been infiltrated/compromised. The malicious version was from malvertising/typosquatting sites, and signed by random compromised certifications - not by the KeePass developer.

    I guess what they're intending to emphasize is that the malware authors recompiled KeePass to add their malware as opposed to just packaging it alongside KeePass in an installer, but it did initally sound like something far worse had happened.