Recommended Free Tools
Pidgin’s third-party ss-otr plugin was confirmed to contain a keylogger, and Pidgin advised anyone who installed it to uninstall it. Separately, SecurityWeek reported that ESET found similar malicious code in Cradle, an unofficial Signal fork—not an official Signal app. The available reports do not establish how many people or devices were affected.
What was the Pidgin ss-otr plugin incident?
On August 22, 2024, Pidgin said a plugin named ss-otr had been added to its third-party plugins list on July 6. The project said it received a report on August 16 that the plugin contained a keylogger and was sharing screenshots with unwanted parties. Pidgin removed the plugin and later confirmed the keylogger. Pidgin’s incident notice advises anyone who installed it to uninstall it.
The project also said the plugin supplied downloadable binaries without source code. Pidgin’s developers wrote: “It went unnoticed at the time that the plugin was not providing any source code and was only providing binaries for download.” In response, they said Pidgin would require linked plugins to use an OSI-approved open-source license and would introduce some level of due diligence to verify plugin safety.
What malicious behavior was reported?
Confirmed by Pidgin
Pidgin confirmed the plugin contained a keylogger and said it shared screenshots with unwanted parties. The project did not publish a count of users, installations, or devices affected.
#1 Best Overall
Additional findings attributed to ESET
SecurityWeek’s August 28, 2024 report attributed additional technical findings to ESET: the plugin could download and execute scripts and the DarkGate malware, and similar backdoor code was found in Cradle. SecurityWeek said DarkGate has been used to steal credentials, log keystrokes, and provide remote desktop capabilities. These are findings as relayed by SecurityWeek, rather than details confirmed in Pidgin’s notice. Read SecurityWeek’s report.
SecurityWeek also reported Linux versions of the malicious plugin and Cradle. The reports do not establish that every installation was infected or provide a verified scale of impact.
Rank #2
Is Cradle an official Signal app?
No. SecurityWeek described Cradle as an open-source Signal fork advertised as anti-forensic messaging software, and expressly said it was not sponsored by or related to Signal Messenger or the Signal Foundation. The reported presence of similar backdoor code in Cradle should not be read as evidence that the official Signal app was involved.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should ss-otr users do?
If you installed the ss-otr plugin, follow Pidgin’s explicit advice and uninstall it. The cited reports do not document a broader cleanup procedure, so uninstalling should not be treated as proof that a potentially compromised device has been fully remediated. For current indicators of compromise or download status, consult a current primary security advisory; the cited incident reports do not establish either.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteQuick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

