{"id":1092,"date":"2026-06-09T15:54:55","date_gmt":"2026-06-09T10:24:55","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1092"},"modified":"2026-08-19T16:02:22","modified_gmt":"2026-08-19T10:32:22","slug":"hola-browser-supply-chain-attack","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/","title":{"rendered":"Hola Browser Supply Chain Attack: How a Trusted Browser Distribution Channel Delivered a Cryptominer"},"content":{"rendered":"<h2>Introduction<\/h2>\n<p>Most users trust that software downloaded from an official source is safe to install. The Hola Browser supply chain attack, disclosed in June 2026, challenged that assumption after investigators discovered that some Windows installations of Hola Browser included an undeclared executable that appeared to be a cryptocurrency miner.<\/p>\n<p>A compromise in Hola Browser\u2019s Windows software delivery process caused the issue, rather than the browser\u2019s intended functionality.<\/p>\n<p>The incident highlights a broader concern: trusted software distribution channels can provide a pathway into otherwise well-protected environments.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" target=\"_blank\">\r\n    \t\tStrengthen Endpoint Visibility with Hexnode <\/a>\r\n    \t\t<\/center><\/p>\n<h2>Why Trusted Software Became the Attack Vector<\/h2>\n<p>One of the most concerning aspects of the Hola Browser supply chain attack is that software users expected to trust delivered the malicious activity. Rather than targeting individual users through phishing emails or exploiting vulnerabilities on specific devices, the compromise affected the software delivery process itself.<\/p>\n<p>This approach can make malicious activity harder to identify because the software originates from a legitimate vendor and appears to be a normal installation.<\/p>\n<p>In this case, some Windows installations of Hola Browser reportedly included an undeclared executable that was not part of the expected software package. The file was later associated with cryptocurrency mining activity and persistence mechanisms on affected systems.<\/p>\n<p>The incident serves as a reminder that software trust should not end at installation. Even when applications come from legitimate sources, organizations benefit from monitoring application behavior, validating software integrity, and investigating unexpected changes on endpoints. This layered approach can help security teams identify suspicious activity when trusted software behaves in unexpected ways.<\/p>\n<h2>How the Hola Browser supply chain attack works<\/h2>\n<table style=\"font-weight: 400;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"12\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Category<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Details<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Disclosure date<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">June 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Threat actor<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Not publicly\u00a0identified<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Initial access method<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Not publicly confirmed<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Delivery mechanism<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Undeclared executable delivered through affected Hola Browser for Windows installations<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Social engineering<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">None reported<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Target platforms<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Windows<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Infrastructure<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Hola Browser Windows software delivery\u00a0pipeline<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">User action\u00a0required<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Installation\u00a0of an affected Hola Browser for Windows build<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Data at risk<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">No\u00a0evidence\u00a0of user data access, theft,\u00a0or compromise has been reported<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Confirmed impact<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Delivery\u00a0of an undeclared executable identified as a cryptocurrency miner; creation\u00a0of persistence mechanisms; Microsoft Defender exclusion modification<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Unconfirmed impact<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Credential theft, remote access, lateral movement, ransomware deployment, and data exfiltration have not been reported or confirmed<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Key Findings from the Investigation<\/h3>\n<p>Investigators identified an undeclared executable named me.exe in the Hola installation directory on some Windows systems.<\/p>\n<p>Analysis revealed several suspicious characteristics:<\/p>\n<ul>\n<li>The file was not digitally signed.<\/li>\n<li>It lacked a timestamp.<\/li>\n<li>It contained obfuscated code.<\/li>\n<li>It was not part of the browser&#8217;s declared software package.<\/li>\n<li>The file could write to memory.<\/li>\n<\/ul>\n<p>The binary also exhibited behavior commonly associated with cryptomining malware:<\/p>\n<ul>\n<li>Creating a Defender exclusion.<\/li>\n<li>Copying itself as HolaMonitorService.exe.<\/li>\n<li>Registering an auto-starting service named hola_monitor_svc.<\/li>\n<li>Running primarily when the device was idle.<\/li>\n<\/ul>\n<p>Investigators observed indicators suggesting the executable was based on XMRig-related mining functionality and operated as a Monero miner.<\/p>\n<h3>What Remains Unclear in the Hola Browser supply chain attack<\/h3>\n<p>Several important details have not been publicly confirmed:<\/p>\n<ul>\n<li>The identity of the attackers.<\/li>\n<li>How access to the distribution pipeline was obtained.<\/li>\n<li>The exact duration of the compromise.<\/li>\n<li>Whether additional payloads were tested or distributed.<\/li>\n<li>Whether specific geographic regions were disproportionately affected.<\/li>\n<\/ul>\n<p>Hola reported that approximately <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hola-browser-for-windows-compromised-to-deliver-cryptominer\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=hola_browser_supply_chain_attack\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">0.1% of users<\/a> were impacted and stated that there was no evidence of user data access, theft, or compromise.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-windows-management-solution-1-1-300x225-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Hexnode Windows Management Solution\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-windows-management-solution-1-1-300x225-1.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-windows-management-solution-1-1-300x225-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" title=\"hexnode-windows-management-solution-1-1-300x225\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode Windows Management Solution\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            See how organizations can leverage Hexnode's Windows management capabilities to efficiently manage their corporate Windows devices.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/datasheets\/hexnode-windows-management-solution\/'>\n                            Download the Datasheet\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>Why this Hola Browser supply chain attack matters<\/h2>\n<p>This incident apparently resulted in unauthorized cryptocurrency mining. However, the larger concern is the <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-attack-path\/\">attack path<\/a> itself.<\/p>\n<p>Organizations often place significant trust in software obtained directly from vendors. When attackers gain access to a trusted distribution mechanism, traditional allowlisting and reputation-based controls may be less effective because the software appears legitimate at the point of installation.<\/p>\n<p>The incident also demonstrates why Windows endpoint security programs increasingly rely on behavioral monitoring rather than signatures alone. Activities such as unauthorized service creation, suspicious persistence mechanisms, unsigned executable deployment, and Defender exclusion changes can reveal malicious behavior even when it originates from trusted software.<\/p>\n<p>As software ecosystems continue to grow more interconnected, maintaining visibility into application behavior becomes just as important as validating the source of the software itself.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/All-Images-6_11zon-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Ensure Software Supply Chain Security with Hexnode UEM<\/h4><p>Learn how organizations can use Hexnode UEM to ensure real-time software supply chain security.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/ensure-software-supply-chain-security-with-hexnode-uem\/\" aria-label=\"Ensure Software Supply Chain Security with Hexnode UEM\"><\/a><\/div><\/div><\/div><\/p>\n<h2>How Hexnode Can Help Reduce Risk<\/h2>\n<h3>Hexnode UEM: Improve Application Governance and Device Compliance<\/h3>\n<p>The Hola Browser supply chain attack demonstrates why organizations need visibility and control over the software running on managed endpoints.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can help organizations:<\/p>\n<ul>\n<li>Enforce approved application policies.<\/li>\n<li>Manage software deployment across <a href=\"https:\/\/www.hexnode.com\/uem\/platform\/windows-mdm\/\">Windows<\/a> devices.<\/li>\n<li>Control unauthorized applications through blocklisting\/allowlisting and compliance enforcement.<\/li>\n<li>Validate device compliance against organizational policies.<\/li>\n<li>Remotely remove managed applications from Windows devices when required.<\/li>\n<\/ul>\n<p>While no device management platform can guarantee prevention of a supply-chain compromise, strong <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-application-control\/\">application control<\/a> and UEM compliance practices can help reduce exposure and simplify response efforts when trusted software contains unexpected components.<\/p>\n<h3>Hexnode XDR: Investigate Suspicious Endpoint Activity<\/h3>\n<p>Supply-chain attacks often become visible through the behavior of the delivered payload rather than the initial installation process.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> helps security teams investigate suspicious endpoint activity and support response actions, such as device isolation and process termination, when they identify malicious activity.<\/p>\n<h2>Closing the Gaps Exposed by This Attack<\/h2>\n<p>The Hola Browser supply chain attack is a reminder that trusted software distribution channels remain attractive targets for attackers.<\/p>\n<p>Although the payload focused on cryptocurrency mining and users have not reported any data compromise, the incident illustrates how compromising software distribution infrastructure can turn a legitimate application into a delivery mechanism for unauthorized code.<\/p>\n<p>Organizations should review software governance processes, validate application inventories, monitor for unexpected endpoint behavior, and ensure they can rapidly investigate suspicious activity across managed devices.<\/p>\n<p>Combining application management, compliance enforcement, endpoint investigation, and supported response actions can help reduce exposure to software supply chain compromises.<\/p>\n<p>As attackers continue to target trusted delivery mechanisms, organizations should focus not only on where software comes from but also on how that software behaves after installation.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stay Ahead of Emerging Endpoint Threats<\/h5><p>Get practical threat intelligence, endpoint security insights, and incident analysis delivered directly to your inbox.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Try Hexnode Now<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Introduction Most users trust that software downloaded from an official source is safe to install&#8230;.<\/p>\n","protected":false},"author":4,"featured_media":1094,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[11,16],"class_list":["post-1092","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ransomware","category-windows","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hola Browser Supply Chain Attack Delivers Cryptominer<\/title>\n<meta name=\"description\" content=\"Hola Browser supply chain attack delivered a Monero miner to some Windows users, highlighting software trust and endpoint security risks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hola Browser Supply Chain Attack Delivers Cryptominer\" \/>\n<meta property=\"og:description\" content=\"Hola Browser supply chain attack delivered a Monero miner to some Windows users, highlighting software trust and endpoint security risks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-09T10:24:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T10:32:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HolaBrowserSupplyChainAttac.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1500\" \/>\n\t<meta property=\"og:image:height\" content=\"843\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Hola Browser Supply Chain Attack: How a Trusted Browser Distribution Channel Delivered a Cryptominer\",\"datePublished\":\"2026-06-09T10:24:55+00:00\",\"dateModified\":\"2026-08-19T10:32:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/\"},\"wordCount\":1020,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/HolaBrowserSupplyChainAttac.jpeg?format=webp\",\"articleSection\":[\"Ransomware\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/\",\"name\":\"Hola Browser Supply Chain Attack Delivers Cryptominer\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/HolaBrowserSupplyChainAttac.jpeg?format=webp\",\"datePublished\":\"2026-06-09T10:24:55+00:00\",\"dateModified\":\"2026-08-19T10:32:22+00:00\",\"description\":\"Hola Browser supply chain attack delivered a Monero miner to some Windows users, highlighting software trust and endpoint security risks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/HolaBrowserSupplyChainAttac.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/HolaBrowserSupplyChainAttac.jpeg?format=webp\",\"width\":1500,\"height\":843,\"caption\":\"Hola Browser Supply Chain Attack\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/hola-browser-supply-chain-attack\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hola Browser Supply Chain Attack: How a Trusted Browser Distribution Channel Delivered a Cryptominer\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hola Browser Supply Chain Attack Delivers Cryptominer","description":"Hola Browser supply chain attack delivered a Monero miner to some Windows users, highlighting software trust and endpoint security risks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/","og_locale":"en_US","og_type":"article","og_title":"Hola Browser Supply Chain Attack Delivers Cryptominer","og_description":"Hola Browser supply chain attack delivered a Monero miner to some Windows users, highlighting software trust and endpoint security risks.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-09T10:24:55+00:00","article_modified_time":"2026-08-19T10:32:22+00:00","og_image":[{"width":1500,"height":843,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HolaBrowserSupplyChainAttac.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Hola Browser Supply Chain Attack: How a Trusted Browser Distribution Channel Delivered a Cryptominer","datePublished":"2026-06-09T10:24:55+00:00","dateModified":"2026-08-19T10:32:22+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/"},"wordCount":1020,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HolaBrowserSupplyChainAttac.jpeg?format=webp","articleSection":["Ransomware","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/","url":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/","name":"Hola Browser Supply Chain Attack Delivers Cryptominer","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HolaBrowserSupplyChainAttac.jpeg?format=webp","datePublished":"2026-06-09T10:24:55+00:00","dateModified":"2026-08-19T10:32:22+00:00","description":"Hola Browser supply chain attack delivered a Monero miner to some Windows users, highlighting software trust and endpoint security risks.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HolaBrowserSupplyChainAttac.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/HolaBrowserSupplyChainAttac.jpeg?format=webp","width":1500,"height":843,"caption":"Hola Browser Supply Chain Attack"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/hola-browser-supply-chain-attack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Hola Browser Supply Chain Attack: How a Trusted Browser Distribution Channel Delivered a Cryptominer"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1092","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1092"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1092\/revisions"}],"predecessor-version":[{"id":1099,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1092\/revisions\/1099"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1094"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1092"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1092"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}