Security Alert: Keylogging Plugin Discovered in Pidgin Messaging App

Critical warning: Pidgin users warned of ss-otr plugin containing a keylogger, shares screenshots. Immediate uninstall is advised.

In a concerning turn of events, the Pidgin messaging app was the unfortunate host of a malicious plugin that compromised user security.

The plugin, named ss-otr (ScreenShareOTR), was initially added to Pidgin’s third-party plugin roster on July 6th; unbeknownst to users and developers, it harbored harmful components.

The alarming discovery was made on August 16th when an alert was raised by the user, who reported that the plugin contained a keylogger and was capable of capturing screenshots to send to unauthorized parties.

This report prompted immediate action from the Pidgin team, who promptly removed the plugin from their listing and began an in-depth investigation into the breach.

Subsequent verification on August 22nd confirmed the presence of the keylogger, cementing the plugin’s status as a significant security threat. Users who have installed ss-otr are strongly advised to remove it from their systems immediately.

Interestingly, at the time of its approval, the ss-otr plugin provided only binary files for download, with no source code availableโ€”a detail that went overlooked but highlighted a critical oversight in the vetting process.

In response to this incident, the Pidgin team has announced new measures to bolster security for its plugin ecosystem. Moving forward, all plugins must be accompanied by an OSI Approved Open Source License, and thorough due diligence will be conducted to ensure the safety and reliability of the plugin for users.

Yes, I know Pidgin isn’t as popular as it was a decade ago, but it’s still being supported. So, if you’ve bet on it, review the plugins you use. For more information, refer to the announcement.

Bobby Borisov

Bobby Borisov

Bobby, an editor-in-chief at Linuxiac, is a Linux professional with over 20 years of experience. With a strong focus on Linux and open-source software, he has worked as a Senior Linux System Administrator, Software Developer, and DevOps Engineer for small and large multinational companies.

Think You're an Ubuntu Expert? Let's Find Out!

Put your knowledge to the test in our lightning-fast Ubuntu quiz!
Ten questions to challenge yourself to see if you're a Linux legend or just a penguin in the making.

1 / 10

Ubuntu is an ancient African word that means:

2 / 10

Who is the Ubuntu's founder?

3 / 10

What year was the first official Ubuntu release?

4 / 10

What does the Ubuntu logo symbolize?

5 / 10

What package format does Ubuntu use for installing software?

6 / 10

When are Ubuntu's LTS versions released?

7 / 10

What is Unity?

8 / 10

What are Ubuntu versions named after?

9 / 10

What's Ubuntu Core?

10 / 10

Which Ubuntu version is Snap introduced?

The average score is 68%