Linux builds of Cemu 2.6 were compromised with malware between May 6 and May 12, 2026.
Affected files:
- Cemu-2.6-x86_64.AppImage
- cemu-2.6-ubuntu-22.04-x64zip
>The malware could steal passwords, browser session tokens, SSH keys, GitHub credentials, cloud access tokens, and other sensitive authentication data.
>The compromise originated from a stolen developer GitHub token used to replace official Linux release binaries on GitHub.
>Windows, macOS, and Flatpak versions were unaffected.
If you downloaded or executed the affected builds, take these steps:
- Reinstall your operating system
- Change passwords for important accounts
- Revoke and regenerate SSH keys, GitHub tokens, API keys, and cloud credentials
- Remove the compromised binaries
- Review your system for unauthorized access