Malware installed in Click Studios’ Passwordstate update director could expose 29,000 users to exfiltration of passwords. Malware could pull account’s username and password along with the computer name, the user’s name, domain name, current process name, process ID, all running processes’ names and IDs. Malicious download of malicious Passwordstate_upgrade.zip file was a modified moserware.secretsplitter.dll, with a size of 65KB. Click Studios advises customers to scan their systems for clues to see if they downloaded the malicious.”]
Source: https://www.careersinfosecurity.com/click-studios-hacked-exposing-users-passwords-a-16469