[HN Gopher] CPU-Z and HWMonitor compromised
       ___________________________________________________________________
        
       CPU-Z and HWMonitor compromised
        
       https://xcancel.com/vxunderground/status/2042483067655262461
       https://old.reddit.com/r/pcmasterrace/comments/1sh4e5l/warni...
       https://www.bleepingcomputer.com/news/security/supply-chain-...
        
       Author : pashadee
       Score  : 227 points
       Date   : 2026-04-10 13:29 UTC (9 hours ago)
        
 (HTM) web link (www.theregister.com)
 (TXT) w3m dump (www.theregister.com)
        
       | kevincloudsec wrote:
       | same threat group hit filezilla last month. they're specifically
       | targeting utilities that tech-savvy users trust and download from
       | official sources. the attack surface is the the api layer that
       | generates download links, not the binary itself
        
       | kevincloudsec wrote:
       | same threat group hit filezilla last month with a fake domain.
       | this time they didn't even need a fake domain, they compromised
       | the real one's api layer. the attack is evolving from 'trick
       | users into visiting the wrong site' to 'make the right site serve
       | the wrong file.'
        
       | cachius wrote:
       | This is bad. I like to install software with winget. Are the
       | versions there also compromised?
       | 
       | v1.63 updated 6 days ago https://github.com/microsoft/winget-
       | pkgs/tree/master/manifes... via
       | https://winstall.app/apps/CPUID.HWMonitor
       | 
       | v2.19 updated 15 days ago https://github.com/microsoft/winget-
       | pkgs/tree/master/manifes... via
       | https://winstall.app/apps/CPUID.CPU-Z
        
       | cachius wrote:
       | It's HWMonitor https://www.cpuid.com/softwares/hwmonitor.html and
       | not HWInfo https://www.hwinfo.com/
       | 
       | So two programs from CPUID. I wonder if there are more affected.
       | 
       | Same topic on Reddit at
       | https://news.ycombinator.com/item?id=47718830 @dang
        
       | wang_li wrote:
       | Jesus. I see that post and comment section and I immediately
       | expect to hear Joey telling me about how this ATM is Idaho
       | started spraying cash after his hack of the Gibson. That is a
       | real-life reproduction of the perception of hackers in films in
       | the '90s.
        
         | metalliqaz wrote:
         | someone has some l33t sk1llz
        
         | vntok wrote:
         | From the thread:
         | 
         | > Q: Why the heck did you hyperlink [the malware installer]?
         | 
         | > A: If someone reads this and they still click the download
         | then they kind of deserve the virus tbh
        
         | daneel_w wrote:
         | And CSI: Miami, which kept the vibe alive through the 2000s and
         | "educated the masses" on how IT works. Beep boop, I'm in.
        
           | vntok wrote:
           | The counter-hacker double-keyboarding sequence was inspiring.
        
       | orthogonal_cube wrote:
       | Seems the installers hosted by them are fine. The links on the
       | site have been changed to direct people towards Cloudflare R2
       | storage with various copies of malicious executables.
       | 
       | Looking forward to information down the line on how this came
       | about.
        
         | 1970-01-01 wrote:
         | Not exactly a supply chain compromise, as devs should be smart
         | enough to update via a package manager such as winget and
         | chocolatey, but it certainly fits for a watering hole attack.
        
           | Terr_ wrote:
           | I suppose one could view it as a supply-chain compromise of
           | an alternate chain that's very short.
        
       | john_strinlai wrote:
       | some comments purportedly (i did not verify) from one of the
       | maintainers:
       | 
       | > _Dear All, I 'm Sam and in I'm working with Franck on CPU-Z
       | (I'm doing the validator). Franck is unfortunately OOO for a
       | couple weeks. I'm just out of bed after worked on Memtest86+ for
       | most the night, so I'm doing my best to check everything. As very
       | first checks, the file on our server looks fine
       | (https://www.virustotal.com/gui/file/6c8faba4768754c3364e7c40...)
       | and the server doesn't seems compromised. I'm investigating
       | further... If anyone can tell me the exact link to the page where
       | the malware was downloaded, that would help a lot_
       | 
       | > _Thank you. I found the biggest breach, restored the links and
       | put everything in read-only until more investigation is done.
       | Seems they waited Franck was off and I get to bad after working
       | on Memtest86+ yesterday :- /_
       | 
       | > _The links have been compromised for a bit more than 6 hours
       | between 09 /04 and 10/04 GMT :-/_
       | 
       | so, it appears that the cpuid _website_ was compromised, with
       | links leading to fake installers.
        
         | BoredPositron wrote:
         | It's the third time that I've read something about availability
         | notifications on discord and other chats getting abused for
         | timed attacks in the last few weeks.
        
           | magicalhippo wrote:
           | After my Wordpress site got hacked way back through an
           | exploit in one of the WP files, I set up a cron job that
           | compared the hash of the static files with expected hash, and
           | would fire off an email if they differed.
           | 
           | The script lived above the web root, so they'd have to escape
           | that to tamper with it, and was generated by another script.
           | 
           | Saved me a couple of times since, well worth the 15 minutes I
           | spent on setting it up.
        
             | embedding-shape wrote:
             | > Saved me a couple of times since
             | 
             | Wait, how often does your Wordpress site get successfully
             | hacked like that?
        
               | magicalhippo wrote:
               | Keep in mind the first time was about 20 years ago.
               | 
               | One time the hosting provider got compromised, FTP server
               | exploit IIRC, they ran a recursive search and replace
               | from root directory of the server.
        
               | Beretta_Vexee wrote:
               | It depends on how long you've been using WordPress,
               | whether you use plugins, whether they're well-maintained
               | or not, and so on.
               | 
               | Back around 2010, there were security vulnerabilities in
               | WordPress or its popular plugins almost every month.
        
             | michaelt wrote:
             | Back in the 1990s, there was a tool called 'tripwire' that
             | checked key files against expected checksums.
             | 
             | As I recall, they recommended putting the expected values
             | on a floppy disk and setting the 'write protect' tab, so
             | the checksums couldn't be changed.
        
               | Terr_ wrote:
               | Back in the 90s I fantasized about a hard drive bay with
               | a physical write-protect switch on the cover plate.
        
               | kqgnkqgn wrote:
               | In the mid-2000's I briefly worked for a company that did
               | this at a firmware level ("write-blocked firmware") for
               | USB drive adapters (IDE / SATA / whatever IDE variant
               | laptops were using / etc). This was apparently very
               | valuable for police and investigative services, so they
               | could collect evidence, while being able to show that
               | they did not tamper with the original drive.
        
               | kjs3 wrote:
               | Tenable makes some "read only" adapters for hard disks
               | (SATA, PATA, SCSI & FW at least). They're usually sold as
               | part of a forensic analysis kit. I have a couple and they
               | definitely work. I believe there are a couple of other
               | vendors (Wiebetech?) make similar devices.
               | 
               | The alternative (tho not practical in many cases) would
               | be RO media like RW-DVD.
        
               | FuriouslyAdrift wrote:
               | tripwire was the orginal file integrity anti-virus/anti-
               | tampering software from the security group (which turned
               | into CERIAS) at Purdue led by Dr. Eugene "Spaff"
               | Spafford.
               | 
               | https://docs.lib.purdue.edu/cstech/1084/
        
               | Bender wrote:
               | For some time a number of people and companies have been
               | using OSSEC for that job. [1] There are a couple versions
               | of it _free open source and enterprise_. There are a
               | handful of other programs that also keep an eye on
               | checksums.
               | 
               | If tinkering with OSSEC one of the first steps should be
               | to configure whitelisting for IP ranges and CIDR blocks
               | used by your company, SNAT addresses and bastion IP's so
               | that someone does not lock everyone out. It does a lot
               | more than checksums.
               | 
               | [1] - https://www.ossec.net/
        
             | daneel_w wrote:
             | Related: OpenBSD does this daily as part of running
             | security(8) and its coverage can be expanded to include
             | pretty much anything.
             | 
             | https://man.openbsd.org/security
        
           | Aurornis wrote:
           | Can you share what those other attacks were? It's helpful to
           | study additional attacks to know what to look for.
        
         | cwizou wrote:
         | For what it's worth - I used to write CPU reviews a while back
         | - I can vouch for both Sam and Franck. Franck is the guy behind
         | CPUID and Sam is a close friend of his, who was known for
         | working at Canard PC on top of his work on Memtest :
         | https://x86.fr/about-me/
        
           | john_strinlai wrote:
           | that is pretty cool!
           | 
           | when i say i didnt verify, i just mean that i ripped these
           | quotes out of reddit, and did not check whether the reddit
           | username that posted the comments is known to be an identity
           | of Sam.
        
             | cwizou wrote:
             | I didn't talk to him to verify, but at the very least it's
             | his username (and the account is old enough at this point :
             | https://www.reddit.com/user/Doc_TB/comments/), and his
             | _very_ Belgian english.
             | 
             | I know both are close and Sam handles his website, so since
             | the links are fixed, I have near zero doubt it's Sam here
             | on reddit.
        
         | pseudosavant wrote:
         | Glad that they figured out the issue and fixed the links. When
         | I first read this, I assumed it was actually the sketchy ads
         | that are run on www.cpuid.com.
         | 
         | These are the real ads I just saw on a single download page for
         | CPU-Z: "Continue to Download", "Install For windows 10, 11
         | 32/64 bit Get Fast!", "Download", "Download now from PC APP
         | STORE", or "Download Now For windows 10, 11 32/64 bit". Many of
         | them appeared multiple times on the page.
         | 
         | The real download links don't even say they are download links.
         | 
         | I love the winget CLI in this situation. This is all you need:
         | `winget install CPUID.CPU-Z`.
        
           | sysworld wrote:
           | Personally I'm fine with the scammy ads. I feel most people
           | who would use CPU-Z are pretty technical and should be able
           | to tell the difference between an ad download button vs the
           | real one.
           | 
           | That, and you should already be using an ad blocker.
        
         | cluckindan wrote:
         | Any idea how the compromise was achieved?
        
           | john_strinlai wrote:
           | i have no clue. i yoinked these quotes from the reddit thread
           | where sam replied.
           | 
           | i am sure that we will see a write-up once the investigation
           | concludes. it hasnt even been a day yet though, so i imagine
           | sam is still in damage-control mode rather than root cause
           | analysis mode.
        
       | amatecha wrote:
       | some good details here
       | https://xcancel.com/vxunderground/status/2042483067655262461
        
       | kyrra wrote:
       | For windows users, this is an advantage of using `winget` for
       | installing things. It points to the installer hosted elsewhere,
       | but it at least does a signature check. The config for the latest
       | installer is listed here: https://github.com/microsoft/winget-
       | pkgs/blob/master/manifes...
       | 
       | which you can install with:                  winget install
       | --exact --id CPUID.CPU-Z
       | 
       | (there is a --version flag where you can specify "2.19", which
       | the signature there is a month old, so it should be safe to
       | install that way)
        
         | ww520 wrote:
         | Yes. Winget is getting better support on Windows apps. The
         | other day I tried to download the latest version of ImageMagick
         | but all the links on the official site were bad. I tried Winget
         | and it had it!
        
         | eviks wrote:
         | This manifest only shows sha checks, which wouldn't help if the
         | manifest is updated during the site compromise. How does it do
         | the signature check?
        
           | actionfromafar wrote:
           | Presumably the manifest is in github and won't auto-update
           | when something on the CPU-Z website changes?
        
             | eviks wrote:
             | What do you mean, how would it get the new version
             | name/hash if not following the changes on the website?
        
               | kyrra wrote:
               | I think you should spend the 5 minutes it takes to look
               | at the winget-pkg repo to see how it works. There's lots
               | of great documentation.
               | 
               | All updates are manual, and are done via pull requests.
               | Check everything in-queue:
               | https://github.com/microsoft/winget-pkgs/pulls
               | 
               | Existing versions don't tend to have their metadata
               | updated (I'm not sure winget would accept it). Only new
               | versions are supported.
               | 
               | You can see all the checks that go into cpu-z updates
               | with the latest PR: https://github.com/microsoft/winget-
               | pkgs/pull/349095
        
               | eviks wrote:
               | That would obviously be longer than 5 minutes; presumably
               | you've done that and still can't answer the simple
               | question
               | 
               | > All updates are manual, and are done via pull requests.
               | 
               | The pull requests can be and some are automated, so not
               | all are manual. But more importantly, how would it help?
               | 
               | > Existing versions don't tend to have their metadata
               | updated (I'm not sure winget would accept it). Only new
               | versions are supported.
               | 
               | The attack is version update! How is the old manifest
               | version relevant here?
               | 
               | > You can see all the checks that go into cpu-z updates
               | with the latest PR:
               | 
               | > Description : Invoke an Azure Function > Static
               | Analysis > Status: Started > Status: InProgress
               | 
               | Excellent, now how can I get the answer to the question
               | from this valuable information?
        
         | hypeatei wrote:
         | Package managers also saved people from the Notepad++ hijack
         | that was disclosed a couple months ago.
         | 
         | I think devs should avoid distributing their software on first
         | party sites unless they're willing to dedicate a bunch of time
         | to making sure all the infra is secure. Not a lot of people
         | verify signatures, but it's also good to have your PKI in order
         | (signing keys should be available on multiple channels)
        
         | fuzzy2 wrote:
         | No, WinGet does not generally protect against this. While PRs
         | to update package versions are verified in some way before
         | going live, the necessary throughput can only be achieved with
         | shallow checks. A determined actor could easily get a malicious
         | update in, once they control the original source.
         | 
         | Other than that, WinGet is mostly just "run setup.exe". It is
         | not a package manager. It's basically MajorGeeks as a mediocre
         | CLI.
        
       | quantummagic wrote:
       | > after the download my Windows Defender instantly detecting a
       | virus.
       | 
       | > (because i am often working with programms which triggering the
       | defender i just ignored that)
       | 
       | This again shows the unfortunate corrosive effect of false-
       | positives. Probably impossible to solve while aggressively
       | detecting viruses though.
        
         | pshirshov wrote:
         | But sorta possible to solve with source-based distribution and
         | totally possible to solve with pure reproducible builds.
        
           | daveguy wrote:
           | What systems have pure reproducible builds? Does Nix? Any
           | others? From what I understand, it is a very difficult
           | problem.
        
             | pshirshov wrote:
             | https://stal-ix.github.io/ and Guix, but the definitions of
             | purity are different for them.
             | 
             | Yes, a very difficult problem, compilers must be pure
             | functions with thin effectful wrappers.
        
           | gertop wrote:
           | It's entirely possible to ship malware in source form... Just
           | look at the numerous supply chain attacks. Nix is a cute
           | project but entirely irrelevant here.
        
             | miniBill wrote:
             | It is possible but visible, and it means burning an
             | identity, so it's not irrelevant
        
         | eviks wrote:
         | If only there were a great Windows app store or a package
         | manager to help with the impossible...
        
         | vegadw wrote:
         | I think to an extent Microsoft is the guilty party here. For
         | may cracks Windows Defender will trip saying "Win32/Keygen"
         | even if there's no actual malware
         | 
         | https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo...
         | 
         | This trains people that do a lot of piracy to be used to
         | turning off their antivirus to let something through, which is
         | fine until it's not. It's like drugs, if we know a subset of
         | the population will do them no matter what, we should make it
         | safe for them to the extent we can. False positives, causing
         | people to ignore actual positives, creates a market for these
         | things.
        
           | ls612 wrote:
           | I mean this is by design? It makes pirates more likely to get
           | malware, and thus normal people more likely to pay for MS
           | products rather than pirate? You may think its immoral but
           | the incentives line up.
        
       | unethical_ban wrote:
       | I've wondered about this while using CachyOS and their package
       | installer. I don't know what repos do what, I don't really
       | understand the security model of the AUR, and I wonder, if I
       | download a package, how can I know it's legitimate or otherwise
       | by some trusted user of the community vs. some random person?
        
         | cephi wrote:
         | To provide some quick information (I implore others to correct
         | me here):
         | 
         | - CachyOS packages should be coming from known, trusted CachyOS
         | and Arch Linux maintainers. There is still potential for them
         | or their original packages to get compromised (See XZ backdoor)
         | however they are pulling source code from trusted sources so
         | you can generally trust these as much as your trust the OS
         | itself.
         | 
         | - AUR packages are a complete wild west. AUR packages are
         | defined by PKGBUILD files and I highly recommend learning how
         | to read PKGBUILDs and always reading them before installation
         | and re-reading them when they are updated. PKGBUILDs for AUR
         | packages can be treated as untrusted shell scripts and to a
         | certain extent an arbitrary actor can make and upload any
         | PKGBUILD to the AUR. Feel free to use them, but make sure A)
         | they are downloading from trusted sources like the original git
         | repo and B) they are running commands that are expected.
         | 
         | EDIT: Improved accuracy.
        
       | cachius wrote:
       | Grok post linking further sources:
       | https://x.com/i/grok/share/3b870ceb9b424c01bf89afbe0de3bd81
        
       | jl6 wrote:
       | To our new generation of human shields willing to use software
       | releases less than a month old, we salute your sacrifice.
        
         | mikestorrent wrote:
         | Is there a tool out there that you can put software releases
         | into and it will tell you how safe it is? I don't seem to be
         | able to buy anything to do this. Crowdstrike and other modern
         | antivirus may react to it once it's on a device, SAST / SCA
         | tooling will help with CVEs, but there's nothing I can give my
         | users where they can put in some piece of random software and
         | get a reputation metric out the other side, is there?
        
           | Foobar8568 wrote:
           | Beside Virus Total, I am unsure https://www.virustotal.com/
        
             | mikestorrent wrote:
             | Thanks, that's helpful
        
           | __natty__ wrote:
           | Not exactly for software (although there is such section) but
           | I use end of life [0] website. Besides time when certain
           | software will be outdated it also tells you their release
           | time.
           | 
           | [0] https://endoflife.date/
        
           | seanw444 wrote:
           | You could put it into an LLM, since that's what we do for
           | everything else nowadays.
        
           | vladvasiliu wrote:
           | > put in some piece of random software and get a reputation
           | metric out the other side
           | 
           | Well, the enterprise version of ms defender will not only
           | react to it if it does something "weird", but will
           | specifically look at its "reputation" before it runs at all.
           | 
           | However, as another commenter pointed out, this generates a
           | _ton_ of false positives. Basically everything that 's "brand
           | new" is liable to trigger it. Think your freshly compiled
           | hellow_world.exe. So, all in all, people may no longer pay
           | attention to it and just click through all warnings.
        
             | tranceylc wrote:
             | Worked on a minecraft clone on steam that would falsely get
             | flagged by defender as a "bitcoin miner" for YEARS.
        
         | sourcegrift wrote:
         | Thanks the web that produced css programmers who have been
         | taught latest is greatest and shiny gets money.
        
           | leptons wrote:
           | "new, shiny" has never been a problem with CSS. Either
           | browsers support some CSS attribute or they don't.
           | 
           | You're probably thinking about Javascript programmers.
        
         | layer8 wrote:
         | I'm not one to chase the new and shiny, but how do you know a
         | nominally months-old software package isn't a newly compromised
         | version at the time you download it?
        
           | herecomesthepre wrote:
           | Windows has this thing called digital signing with
           | certificates that Linux users like to pretend doesn't exist
           | or in the case of yesterday's Wireguard / VeraCrypt
           | discussion, think it's an evil capitalist scheme to control
           | the world.
           | 
           | Digital signing on Windows predates Mac developer
           | certificates by years but arguably wasn't widely used outside
           | of security-paranoid organizations.
           | 
           | Before someone says Linux offers GPG signing it's mostly
           | useless without a central PKI. Developers offer the public
           | key for download on the same server as the software. If
           | someone uploaded compromised software, surely they would
           | replace the key with their own.
        
             | badsectoracula wrote:
             | > Windows has this thing called digital signing with
             | certificates that Linux users like to pretend doesn't exist
             | 
             | ...or, much more likely, any potential benefits are not
             | worth the negatives.
        
             | BenjiWiebe wrote:
             | Linux package managers (the normal way to install software)
             | use signed packages.
             | 
             | I don't know how easy/hard it would be to compromise that.
        
           | ndriscoll wrote:
           | I don't know about other managers, but nixpkgs has hashes of
           | the package I'm installing, and is a git repo, so I can
           | easily detect a history rewrite, and I have the full history
           | of package changes over time. Since it's a git repo, I can
           | also easily install things as of a given time.
        
         | leptons wrote:
         | I hope you don't think that waiting a month will protect you.
         | Malicious software can wait to be triggered months or years
         | before anything malicious happens.
        
           | BenjiWiebe wrote:
           | It helps. If I were a malware/backdoor author, I have the
           | choice to make it lie idle for a couple months; this would
           | help me get more victims, BUT it gives more time for someone
           | to notice it BEFORE I get any victims at all.
           | 
           | Whereas if it is active immediately, I'm likely to get at
           | least a few victims.
        
         | xandrius wrote:
         | Not fair take, cpuz and hwmonitor are often used on new
         | installations of PCs (or at least for me) to verify hw specs
         | and stuff. Or when I need to do some upgrade work for a desktop
         | computer.
         | 
         | I just go to the trusted site, download what's there and get
         | going. This is not an npm package that a dev is updating on day
         | 0 of its release for being a "human shield", it's literally the
         | first version which comes up when DLing the new software.
        
           | saltcured wrote:
           | Seems like the kind of thing to just have on a bootable thumb
           | drive, to inspect any machine without requiring installation
           | on the fly.
           | 
           | In fact, I think I used to use memtest86+ this way as it is a
           | baked in boot option on Fedora bootable ISO images. (Or at
           | least was in the past, I haven't checked this recently.)
        
             | avazhi wrote:
             | CPU-Z gets updated to recognise new CPUs and memory configs
             | and thus must be downloaded new to recognise the new
             | hardware in a new machine (otherwise it can't recognise it
             | properly). With Memtest sure but CPU-Z is something you
             | actually need the latest version of when you first fire up
             | a new PC.
        
               | saltcured wrote:
               | OK, so a bootable thumb drive rather than a read-only ISO
               | image?
               | 
               | I mean, it should be possible to give it an update
               | function which you can run from any utility host, rather
               | than requiring a live install at the moment you want to
               | test a new machine.
               | 
               | That update function could do normal package management
               | and repository things with digital signature checks, etc.
               | 
               | And it could be done ahead of time to support sneaker-net
               | scenarios, i.e. where you won't have networking on the
               | new machine that is being burned-in/validated.
        
       | BoredPositron wrote:
       | "Bug fixes and general improvements."
       | 
       | Supply chain attacks are easier because changelogs for most
       | software are useless now if they are provided at all.
        
       | moomoo11 wrote:
       | One interesting thing about all this stuff is that we may see a
       | big swing towards paid/trusted solutions for all these type of
       | things.
       | 
       | Maybe the 5-10% of true nerds will go find the l33t open source
       | solutions, but most people will just use some paid solution.
       | 
       | Maybe Steam could build. Or in Windows. Or some SaaS solution for
       | registry.
       | 
       | In exchange you just share your HW info
        
       | ASalazarMX wrote:
       | Just my luck that I needed and downloaded CPU-Z yesterday at
       | work, after not needing it for years. Fortunately my download is
       | not detected as malicious by Virustotal, but what a scare.
        
       | VimEscapeArtist wrote:
       | Wait, people still download unsigned exes from PHP-era websites
       | in 2026? And then act surprised when the download link starts
       | pointing to malware?
       | 
       | At this point if your software isn't distributed through a repo
       | with verifiable builds, you're basically running a malware
       | lottery for your users. The only question is when, not if.
       | 
       | CPUID got lucky it was only 6 hours. Imagine if the attackers had
       | better taste in filenames than "HWiNFO_Monitor_Setup.exe" lmao
        
       ___________________________________________________________________
       (page generated 2026-04-10 23:00 UTC)