Risky Bulletin Newsletter
January 21, 2026
Risky Bulletin: Domain resurrection attacks come to Canonical's Snap Store
Presented by
News Editor
A threat actor is registering expired web domains in order to take over email servers, reset passwords on abandoned developer accounts, and publish malware on the Canonical Snap Store for Linux packages.
At least two developer accounts have been hijacked using this technique, also known as a domain resurrection attack, namely for Snap packages published using email addresses from storewise.tech and vagueentertainment.com.
According to Linux expert and former Canonical dev Alan Pope, the threat actor behind this campaign is a group he believes are located in Croatia.