During an AppEsteem certification test, Sophos X-Ops discovered an undeclared executable called me.exe bundled with Hola Browser that functioned as a crypto-miner, exhibiting suspicious characteristics including lack of code signing and obfuscated code. After being notified, Hola confirmed this was a supply chain compromise affecting 0.1% of users and stated they completely rebuilt their distribution pipeline with enhanced security measures.