Hola Browser Hit by Supply Chain Attack Delivering Cryptocurrency Miner

Last updated: June 5, 2026 Reading time: 3 minutes
Disclosure
Share
Hola Browser Hit by Supply Chain Attack Delivering Cryptocurrency Miner
  • Researchers discovered an undeclared executable inside some Windows installations of Hola Browser during routine certification testing.
  • Sophos identified the file as a Monero cryptocurrency miner capable of adding Defender exclusions and installing a persistent service.
  • Hola confirmed a supply chain compromise and said the incident affected only a small portion of users before the company rebuilt its software distribution pipeline.

The Windows version of Hola Browser suffered a supply chain attack that secretly delivered a cryptocurrency miner to some users, according to findings uncovered during routine application certification checks.

Researchers detected the issue while evaluating Hola Browser through the AppEsteem certification process. The browser had previously passed those assessments, but a recent review revealed an undeclared executable installed alongside the software.

Hola, an Israeli company known for its VPN and proxy services, later confirmed the compromise after receiving reports from AppEsteem. Cybersecurity firm Sygnia also independently identified the incident.

Researchers Discover Suspicious File During Certification Review

Security teams involved in the certification process found an unexpected file named me.exe inside certain Hola Browser installations under the Program Files directory.

The executable immediately raised concerns because it had not been declared for certification. Investigators also found that the file lacked a digital signature and timestamp, contained obfuscated code, and possessed the ability to write directly to memory.

After conducting a deeper analysis, researchers at Sophos concluded that the binary displayed characteristics commonly associated with a Monero cryptocurrency miner. Several embedded strings and behavioral indicators pointed to cryptocurrency mining activity rather than legitimate browser functionality.

The discovery prompted further investigation into how the file reached user systems and whether it formed part of a broader compromise affecting Hola’s software distribution process.

Hidden Miner Established Persistence on Infected Systems

According to Sophos, the malicious program did more than simply mine cryptocurrency.

Researchers found that the malware created exclusions within Microsoft Defender, allowing it to avoid security scans. The executable copied itself into Program Files as HolaMonitorService.exe and created a Windows service, hola_monitor_svc, to maintain persistence.

The miner reportedly activated when the computer was idle, using system resources without quickly drawing user attention.

Security analysts said these actions match cryptomining malware designed to stay active long-term while avoiding detection. The findings suggest attackers inserted the malicious component into Hola’s software supply chain before it reached users.

Hola Rebuilds Distribution Pipeline After Confirming Breach

After receiving the findings from AppEsteem, Hola acknowledged that attackers had compromised part of its distribution process.

The company maintained that the impact remained limited and stated that approximately 0.1 percent of users were affected. Hola also said its investigation found no indication that attackers accessed, stole, or compromised user data.

CEO Avi Raz Cohen said the company has rebuilt its software distribution pipeline and added stronger security safeguards. Cohen said Hola strengthened code-signing, tightened access controls, and added continuous monitoring to prevent unauthorized components in future releases.

He added that the new controls aim to ensure users receive only approved, certified, and properly signed software components.

While Hola has confirmed the compromise and taken remediation steps, questions remain about how the attackers breached the distribution chain and who was responsible. The company has not released further details, and it is unclear whether other platforms were affected.

Before using Hola VPN, read our detailed 2026 review to understand its features, pricing, privacy policy, and whether it remains a safe choice after this supply chain attack.

Share this article

About the Author

Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.

More from Rebecca James

Related Posts