How Expired Domains Became a Crypto Attack Vector
-

According to SlowMist, the attack hinges on expired domains once owned by legitimate Snap Store publishers. When these domains lapse, attackers re-register them and use domain-linked email accounts to reset developer credentials, effectively hijacking trusted publisher accounts with active users and download histories.
Because the malicious code is pushed through routine software updates rather than new installs, users are far more likely to trust and install it. SlowMist confirmed that compromised domains like “storewise[.]tech” and “vagueentertainment[.]com” were used to distribute wallet-impersonating apps — highlighting how fragile trust can be when tied to external infrastructure.
-
linux users always think they’re safe until stuff like this happens