The Elmedia Player and Folx Supply Chain Attack

Updated 5 Oct 2026 · Incident date 19 Oct 2017 · vendor binary

PackageEltima Elmedia Player and Folx for macOS, downloaded from eltima.com on 19 October 2017
Filethe signed application bundle was replaced by a wrapper...

The Elmedia Player and Folx downloads from eltima.com carried the OSX/Proton remote access trojan on 19 October 2017. Attackers replaced the real installers on the official site with signed, trojanized copies.

Only downloads from the Eltima site on that day are affected.

What happened

Attackers replaced the Elmedia Player and Folx downloads on the Eltima website with trojanized versions. ESET confirmed the bad package on the official site at 8:00 AM EDT on 19 October 2017, per ESET. ESET told Eltima at 10:35 AM, and Eltima had replaced the files by 3:10 PM.

The attackers built a signed wrapper app. It started the real application from its Resources folder. It also unpacked and ran OSX/Proton. The wrapper showed a fake window that asked for the administrator password. ESET reports that the signing identity was "Clifton Grimm (9H35WM5TA5)" and that Apple revoked the certificate. The C2 domain was eltima[.]in, registered on 15 October 2017.

BleepingComputer lists what Proton can take. This includes browser passwords, cookies and history, cryptocurrency wallet data, SSH private keys, macOS keychain data, VPN settings and 1Password data. It can also download and run more malware. Malwarebytes adds that the Proton.C variant writes a line to the sudoers file.

The installer is the trusted file. The change was a new executable inside a signed bundle. Vigilance compares the build you trust with the new one and reports a bundle that gains an executable with new powers.

Affected versions

The attack hit the downloads, not one version number. A Mac is affected if the user downloaded Elmedia Player or Folx from eltima.com on 19 October 2017 before the files were cleaned.

Per AppleInsider and the other reports found by search, the built-in update feature and the Mac App Store builds were not changed. Those two points come from search results only, so confirm them with Eltima.

Indicators of compromise

These indicators come from ESET and BleepingComputer.

How to check

Look for the Proton files on the Mac. A hit on any path means the Mac ran the trojanized download.

ls -d /tmp/Updater.app /Library/.rand /Library/.rand/updateragent.app /Library/LaunchAgents/com.Eltima.UpdaterAgent.plist 2>/dev/null

No output means none of the four paths exist.

What to do now

  1. If any path exists, disconnect the Mac from the network.
  2. ESET advises a full reinstall of the operating system. Back up only your documents, not applications.
  3. Change every password that the Mac held or typed. This includes browser passwords, keychain items, and 1Password data.
  4. Replace SSH keys and VPN credentials. Treat cryptocurrency wallet data as stolen.
  5. Install Elmedia Player and Folx again only from a clean source after the reinstall.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Eltima-prev --new Eltima-current
files scanned: 25 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   Eltima.exe
           It downloads from the internet and reads saved passwords and access keys.

Frequently asked questions

When were the Elmedia Player and Folx downloads infected?

On 19 October 2017. ESET confirmed the bad package at 8:00 AM EDT and Eltima cleaned the site by about 3:10 PM EDT.

How do I check if my Mac has OSX/Proton from Eltima?

Look for /tmp/Updater.app, /Library/LaunchAgents/com.Eltima.UpdaterAgent.plist, /Library/.rand and /Library/.rand/updateragent.app. Any of these means the Mac is infected.

How do I remove OSX/Proton?

ESET advises a full reinstall of the operating system and a change of all passwords and keys that the Mac held.

Sources

  1. welivesecurity.com/2017/10/20/osx-proton-supply-chain-attack-elmedia/
  2. bleepingcomputer.com/news/apple/eltima-website-hacked-to-spread-proton-rat-with-popular-video-player-app/
  3. malwarebytes.com/blog/news/2017/10/mac-malware-osx-proton-strikes-again

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free