The Passwordstate In-Place Upgrade Attack

Updated 5 Oct 2026 · Incident date 20 Apr 2021 · vendor binary

PackageClick Studios Passwordstate In-Place Upgrade package (Passwordstate_upgrade.zip) served 20-22 April 2021
Filemoserware.secretsplitter.dll

The Passwordstate In-Place Upgrade package, Passwordstate_upgrade.zip, contained malware between 20 April 2021 at 8:33 PM UTC and 22 April at 12:30 AM UTC. Passwordstate is a password manager from Click Studios.

The malware, named Moserpass, sent stored passwords to the attackers. Only customers who used the in-place upgrade in that window were exposed.

What happened

Attackers compromised the in-place upgrade feature. BleepingComputer reports that the feature fetched the upgrade from a malicious CDN instead of the real Click Studios servers. Click Studios took the CDN down on 22 April at 7:00 AM UTC.

The Hacker News reports that the upgrade zip held a modified DLL named moserware.secretsplitter.dll. That DLL contacted a remote server and fetched a second-stage file, upgrade_service_upgrade.zip, which extracted and sent out data.

According to the Click Studios advisory, as reported by BleepingComputer, the malware collected:

The advisory says encryption keys and database connection strings were not sent. The malware slept for one day, then restarted the collection and upload. Manual upgrades were not affected. Click Studios said the number of affected customers appeared to be very low.

Affected versions

The affected item is the Passwordstate In-Place Upgrade package served in the 28-hour window. The sources name no build numbers.

Click Studios says its customer base is about 29,000 companies. A customer that did not run an in-place upgrade in the window did not get the file.

Indicators of compromise

BleepingComputer states that CSIS Security Group and CrowdStrike published hashes and command server addresses. Check their reports for the exact values.

How to check

Check your upgrade history first. Then look at the DLL in the Passwordstate install folder. This command shows its hash and timestamp.

Get-ChildItem -Path C:\inetpub -Recurse -Filter moserware.secretsplitter.dll -ErrorAction SilentlyContinue | Get-FileHash -Algorithm SHA256

Compare the hash with a copy from a clean installation. Also search the web server for the second-stage file name.

Get-ChildItem -Path C:\ -Recurse -Filter upgrade_service_upgrade.zip -ErrorAction SilentlyContinue

What to do now

  1. Run the Click Studios hotfix package to remove the tampered DLL.
  2. Reset all passwords stored in Passwordstate. Start with systems that face the internet, such as firewalls and VPN.
  3. Reset internal infrastructure credentials and the Passwordstate proxy credentials.
  4. Review logs for use of those credentials since 20 April 2021.
  5. Do not use the in-place upgrade again until you have verified the package.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here an existing DLL gained download, execute and exfiltration behavior. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Click-prev --new Click-current
files scanned: 11

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    moserware.secretsplitter.dll
           It now downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

What happened to the Passwordstate in-place upgrade?

Between 20 and 22 April 2021 the in-place upgrade fetched a malicious package that held a modified DLL. The malware, Moserpass, sent stored passwords and system details to the attackers.

How do I know if my Passwordstate was affected?

Check whether you ran an in-place upgrade between 20 April 20:33 UTC and 22 April 00:30 UTC 2021. Then check moserware.secretsplitter.dll and apply the Click Studios hotfix.

Sources

  1. bleepingcomputer.com/news/security/passwordstate-password-manager-hacked-in-supply-chain-attack/
  2. thehackernews.com/2021/04/passwordstate-password-manager-update.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free