DAEMON Tools Build Pipeline Became the Attack Vector

The issue is no longer a bad installer in isolation. Disc Soft says its build environment was interfered with, which means any DAEMON Tools Lite installer produced during the affected window has to be treated as untrustworthy, not just the file a user happened to download. Disc Soft says it has secured its infrastructure and released malware-free DAEMON Tools Lite 12.6 on May 5. The affected free build was 12.5.1, and the vendor says users who downloaded it since April 8 should remove it; other paid DAEMON Tools products are not affected. A clean replacement release does not erase exposure from installs already pulled from the official site. The threat now extends to any endpoint that trusted the normal download path during the compromise window.

Part of the PlainSec briefing for 2026-05-18

Sources