Following an immediate investigation, the Monero team today also confirmed that its website, GetMonero.com, was indeed compromised, potentially affecting users who downloaded the CLI wallet between Monday 18th 2:30 am UTC and 4:30 pm UTC.
At this moment, it's unclear how attackers managed to compromise the Monero website and how many users have been affected and lost their digital funds.
According to an analysis of the malicious binaries done by security researcher BartBlaze, attackers modified legitimate binaries to inject a few new functions in the software that executes after a user opens or creates a new wallet.
The malicious functions are programmed to automatically steal and send users' wallet seedsort of a secret key that restores access to the walletto a remote attacker-controlled server, allowing attackers to steal funds without any hassle.