Canonical has announced a temporary suspension of the automatic package review system in the Snap Store due to the emergence of packages containing malicious code designed to steal cryptocurrency from users. It remains unclear whether the incident is limited to the publication of malicious packages by third-party authors or if there are security issues directly related to the repository, as the situation is characterized in the official announcement as a "potential security incident."
Details about the incident are promised to be disclosed following the investigation's conclusion. During the investigation, the service will be switched to a manual review mode, requiring all new snap package registrations to undergo manual verification before publication. This change will not affect the uploading and publishing of updates for existing snap packages.
Problems have been identified in the packages ledgerlive, ledger1, trezor-wallet, and electrum-wallet2, released by malicious actors masquerading as official packages from the developers of the noted cryptocurrency wallets while having no actual relation to them. The problematic snap packages have been removed from the repository and are no longer available for search and installation using the snap utility. Incidents of malicious package uploads in the Snap Store have occurred before, for example, in 2018, when packages containing hidden code for cryptocurrency mining were detected in the Snap Store.
Source: opennet.ru
