Cyera researchers say they found 20 malicious PostgreSQL extensions linked to a cross-platform cryptomining campaign, including four Linux samples that no antivirus engine detected in the company’s VirusTotal check. The extensions can turn a database feature into a route for running malware on the host machine.
Cyera Watch analysis
What happened
In its research report, Cyera says 16 of the extensions target Windows and four target Linux. Its analysis links both sets to a campaign whose infrastructure dates back to 2018 and whose payloads install the XMRigCC cryptocurrency miner.
The Linux extensions are the most striking finding: Cyera says its four samples received zero detections from 65 antivirus engines. The company describes one sample as running its payload when the extension is unloaded, then copying itself into the PostgreSQL configuration and adding itself to the list of libraries loaded at startup. Cyera also says one campaign domain was still active during its investigation.
Why it matters
PostgreSQL extensions are executable code, not harmless database decorations. If an attacker can get a malicious extension loaded, the report says it can run inside PostgreSQL and lead to further code on the machine. That gives operators a reason to treat extension provenance and database configuration as security concerns, not merely housekeeping.
Cyera’s detection figures apply to the samples it analysed, not every Linux system or antivirus product. Still, the reported zero detections show how a database-specific route can slip past familiar scanning tools.
Our read
The useful lesson is to know which extensions are installed and who authorised them. Cyera’s report makes a case for looking beyond the database process when investigating unusual activity, especially where extension configuration changes appear without an expected reason. A database can be a surprisingly accommodating host for a miner; it did not volunteer for the job.
What to watch
- Whether other researchers or security vendors identify the same samples and campaign infrastructure.
- Whether PostgreSQL operators publish guidance on auditing extensions and changes to preload configuration.
- Whether the reported command-and-control infrastructure remains active.
Discussion spark: Should database operators allow only an explicit, tightly controlled set of extensions, or does that create too much friction for legitimate workloads?
Sources and evidence
- Malicious PostgreSQL Extensions in the Wild | Cyera (7 October 2026, 13:34 UTC)
not affiliated with or endorsed by Cyera