The Elmedia Player and Folx Supply Chain Attack
Updated 5 Oct 2026 · Incident date 19 Oct 2017 · vendor binary
Eltima Elmedia Player and Folx for macOS, downloaded from eltima.com on 19 October 2017the signed application bundle was replaced by a wrapper...The Elmedia Player and Folx downloads from eltima.com carried the OSX/Proton remote access trojan on 19 October 2017. Attackers replaced the real installers on the official site with signed, trojanized copies.
Only downloads from the Eltima site on that day are affected.
What happened
Attackers replaced the Elmedia Player and Folx downloads on the Eltima website with trojanized versions. ESET confirmed the bad package on the official site at 8:00 AM EDT on 19 October 2017, per ESET. ESET told Eltima at 10:35 AM, and Eltima had replaced the files by 3:10 PM.
The attackers built a signed wrapper app. It started the real application from its Resources folder. It also unpacked and ran OSX/Proton. The wrapper showed a fake window that asked for the administrator password. ESET reports that the signing identity was "Clifton Grimm (9H35WM5TA5)" and that Apple revoked the certificate. The C2 domain was eltima[.]in, registered on 15 October 2017.
BleepingComputer lists what Proton can take. This includes browser passwords, cookies and history, cryptocurrency wallet data, SSH private keys, macOS keychain data, VPN settings and 1Password data. It can also download and run more malware. Malwarebytes adds that the Proton.C variant writes a line to the sudoers file.
The installer is the trusted file. The change was a new executable inside a signed bundle. Vigilance compares the build you trust with the new one and reports a bundle that gains an executable with new powers.
Affected versions
The attack hit the downloads, not one version number. A Mac is affected if the user downloaded Elmedia Player or Folx from eltima.com on 19 October 2017 before the files were cleaned.
- Products: Elmedia Player and Folx for macOS.
- Source: the Eltima website only.
- Cleanup time: ESET reports 3:10 PM EDT. BleepingComputer reports 3:15 PM EDT.
Per AppleInsider and the other reports found by search, the built-in update feature and the Mac App Store builds were not changed. Those two points come from search results only, so confirm them with Eltima.
Indicators of compromise
These indicators come from ESET and BleepingComputer.
/tmp/Updater.app//Library/LaunchAgents/com.Eltima.UpdaterAgent.plist/Library/.rand//Library/.rand/updateragent.app/- The domain
eltima[.]inand the IP address5.196.42[.]123. - SHA1 of trojaned DMG files:
e9dcdae1406ab1132dc9d507fd63503e5c4d41d9,8cfa551d15320f0157ece3bdf30b1c62765a93a5,0400b35d703d872adc64aa7ef914a260903998ca.
How to check
Look for the Proton files on the Mac. A hit on any path means the Mac ran the trojanized download.
ls -d /tmp/Updater.app /Library/.rand /Library/.rand/updateragent.app /Library/LaunchAgents/com.Eltima.UpdaterAgent.plist 2>/dev/null
No output means none of the four paths exist.
What to do now
- If any path exists, disconnect the Mac from the network.
- ESET advises a full reinstall of the operating system. Back up only your documents, not applications.
- Change every password that the Mac held or typed. This includes browser passwords, keychain items, and 1Password data.
- Replace SSH keys and VPN credentials. Treat cryptocurrency wallet data as stolen.
- Install Elmedia Player and Folx again only from a clean source after the reinstall.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 25 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE Eltima.exe It downloads from the internet and reads saved passwords and access keys.
Frequently asked questions
When were the Elmedia Player and Folx downloads infected?
On 19 October 2017. ESET confirmed the bad package at 8:00 AM EDT and Eltima cleaned the site by about 3:10 PM EDT.
How do I check if my Mac has OSX/Proton from Eltima?
Look for /tmp/Updater.app, /Library/LaunchAgents/com.Eltima.UpdaterAgent.plist, /Library/.rand and /Library/.rand/updateragent.app. Any of these means the Mac is infected.
How do I remove OSX/Proton?
ESET advises a full reinstall of the operating system and a change of all passwords and keys that the Mac held.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.