Snap Store suffers malicious app attack, temporarily adds manual review

Canonical's Snap Store team announced that they have recently received reports of security vulnerabilities from some users. Namely, several recently released Snaps may be malicious and capable of stealing users' crypto funds.

Currently, the Snap Store has deleted the reported Snap. A temporary manual review requirement is implemented for new Snap registrations, effective immediately. This human review is intended to prevent malicious actors from registering legitimate app names (or at least legitimate-sounding names) and using them as a way to push malicious Snaps to users.

When a user attempts to register a new Snap, they will be prompted with a "Name reservation requested." The name will be registered after successful manual review by Snap Store staff. Uploading and publishing revisions of existing Snaps will not be affected.

We apologize for any inconvenience this may cause our snap publishers and developers. However, we believe this is the most prudent course of action at this time.

We want to thoroughly investigate this incident without causing any disruption to our systems, and more importantly, we want to ensure our users have a safe and trustworthy experience in the Snap Store.

Please be patient while we investigate. We will provide more detailed updates in the coming days.

If you have recently installed any of the new crypto ledger apps from the Snap Store , you might want to check to see if the app is still on the list. If not, this may mean that it has been taken down due to suspicion of being a malicious program. 

More details can be found on  the Snapcraft forum .

Guess you like

Origin www.oschina.net/news/260114/snap-store-security-incident