The CPUID CPU-Z and HWMonitor Download Compromise

Updated 5 Oct 2026 · Incident date 9 Apr 2026 · vendor binary

PackageCPU-Z 2.19, HWMonitor 1.63, HWMonitor Pro 1.57 and PerfMonitor 2.04 served from cpuid.com, 9-10 April 2026
FileCRYPTBASE.dll added beside the legitimate signed binaries

On 9 and 10 April 2026 the download links on cpuid.com for CPU-Z 2.19, HWMonitor 1.63, HWMonitor Pro 1.57 and PerfMonitor 2.04 led to trojanized files. The installers held a real signed program and a malicious CRYPTBASE.dll. The final payload was STX RAT.

What happened

Attackers changed the download links on the CPUID website so that some downloads came from attacker-controlled hosts. Kaspersky Securelist puts the compromise at about 19 hours, from roughly 15:00 UTC on 9 April to about 10:00 UTC on 10 April 2026. The Scoop issue and SentinelOne describe a shorter window of about six hours, so the exact length is not settled across sources.

The trojanized archives held a legitimate, digitally signed program. A malicious CRYPTBASE.dll sat next to it. Windows loads a DLL from the program folder first, so the signed program loaded the malicious file. This is DLL sideloading.

The loader ran anti-sandbox checks and then contacted a command server. Securelist names the payload STX RAT. SentinelOne reports it can run a hidden VNC session, inject keyboard and mouse input, steal browser credentials, Windows Vault data and crypto wallet data, and download more tools. Persistence uses a registry Run key, a scheduled task and MSBuild project files in AppData\Local.

Securelist counts more than 150 victims, mostly private persons, with some companies in retail, manufacturing and telecommunications. Most infections were in Brazil, Russia and China. SentinelOne notes the attackers reused command infrastructure from a March 2026 FileZilla campaign, so older detection rules caught it.

The software itself was not changed in the vendor build. The change was in what the download contained: one extra DLL beside the signed program. Vigilance reports this type of change when it compares a known good installer with a new one.

Affected versions

Only copies downloaded from cpuid.com during the compromise window are at risk. The Scoop issue shows that package manifests for cpu-z and hwmonitor pointed at the CPUID servers during that time.

Indicators of compromise

These come from Securelist and SentinelOne. Defang domains before you share them.

How to check

You can search a Windows machine for a stray CRYPTBASE.dll outside the Windows folder and check DNS logs for the domains above.

Get-ChildItem -Path C:\ -Filter CRYPTBASE.dll -Recurse -ErrorAction SilentlyContinue | Where-Object { $_.FullName -notlike "C:\Windows\*" }
Get-ScheduledTask | Select-Object TaskName, TaskPath

Review the scheduled task list for tasks you did not create.

What to do now

  1. If you downloaded CPU-Z, HWMonitor, HWMonitor Pro or PerfMonitor on 9 or 10 April 2026, scan the machine for CRYPTBASE.dll.
  2. Remove the DLL and all four persistence items, then run a full malware scan.
  3. Change browser, wallet and account passwords from a clean machine.
  4. Block the domains and IP above at DNS and the firewall.
  5. Download the tools again only from the vendor site, after the vendor confirms the fix.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old CPU-Z-prev --new CPU-Z-current
files scanned: 40 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   CRYPTBASE.dll
           It downloads from the internet.

Frequently asked questions

What happened with the CPU-Z download compromise?

On 9 and 10 April 2026 attackers changed download links on cpuid.com so that some copies of CPU-Z and HWMonitor came with a malicious CRYPTBASE.dll that installed STX RAT.

Which CPU-Z version was affected?

CPU-Z 2.19 was affected. HWMonitor 1.63, HWMonitor Pro 1.57 and PerfMonitor 2.04 were also served in trojanized form.

How do I know if my CPU-Z download was trojanized?

Look for a CRYPTBASE.dll file next to the CPU-Z or HWMonitor program and check for unknown scheduled tasks. A real install does not ship that file.

Sources

  1. securelist.com/tr/cpu-z/119365/
  2. github.com/ScoopInstaller/Extras/issues/17588
  3. sentinelone.com/blog/securing-the-software-supply-chain-how-sentinelones-ai-edr-autonomously-blocked-the-cpu-z-watering-hole-cyber-attack/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free