The official Xubuntu website was compromised by attackers who offered a dangerous ZIP file disguised as an OS download.
The file delivered Windows malware designed to steal cryptocurrency and modify clipboard data.
The ZIP file includes an EXE that runs a fake downloader interface and drops a clipboard hijacker. Do NOT run it.
Users on Reddit's r/Xubuntu community were the first to raise the alarm.
Author's summary: Xubuntu website hacked to spread malware.