Everything in That Folder Runs
A VST3 isn't inert media. It's executable code your DAW can load, which makes every plugin you can't trace back to a trusted source worth another look.

A VST3 isn’t inert media. It’s executable code your DAW can load, which makes every plugin you can’t trace back to a trusted source worth another look.
I’m in Vegas this week for Black Hat and DEF CON, surrounded by people whose job is basically to look at normal software and ask what else it can do. At some point that question crossed over into music production for me, and I started thinking about what’s actually sitting in people’s plugin folders.
Open the folder your DAW scans for plugins.
After enough years making music, it can turn into a kind of sediment. Old installs, utilities you tried once, versions you forgot you still had. Names that make perfect sense until you try to remember exactly where the file came from.
That matters because a plugin isn’t a preset or a sample your DAW just reads. It’s code.
What the format actually does
Steinberg’s VST3 specification describes a plugin module as executable software. On Windows the module contains a DLL. On macOS it’s a bundle containing a Mach-O binary. A host such as Ableton Live discovers those modules, initializes them and loads their components when it needs them.
That sounds obvious when you say it out loud. It doesn’t always feel obvious when you’re staring at a folder full of compressors.
In February 2024, a security researcher publishing as infosecnoodle demonstrated the distinction using Steinberg’s own Hello World VST3 example on Windows. The researcher added a system call, rebuilt the plugin and placed it in the standard VST3 location. Opening the modified plugin in Ableton executed the added command.
The researcher also showed that when Ableton detected a new or modified VST in the plugin directory, plugin initialization could execute code during the scan process. The execution appeared under Ableton Index. For a persistence demonstration, the researcher went further and injected code into AbletonPushCpl.exe, an Ableton-related process that could remain running after the DAW closed.
This wasn’t a vulnerability in Ableton or VST3. It was a proof of concept showing what executable plugin code is capable of doing when you choose to load it.
That’s the part I keep coming back to.
The plugin folder isn’t passive storage. It contains programs your music software may execute.
The old version only wanted your CPU
None of this started with 2026.
In June 2019, ESET documented LoudMiner, a cryptocurrency miner distributed inside pirated audio software for Windows and macOS. ESET traced the campaign back to at least August 2018. One website alone listed 137 VST-related applications, with lures carrying names producers would recognize immediately: Ableton Live, Reason, Sylenth1, Nexus, Reaktor and Auto-Tune.
LoudMiner’s architecture was almost absurdly elaborate for what it wanted. The malware ran mining software inside a virtualized Linux environment, using QEMU on macOS and VirtualBox on Windows.
All that machinery to steal compute.
The 2026 version of this story gets more intimate.
In February, security company Iru published an analysis of a mass-distributed macOS loader disguised predominantly as cracked music software. Researchers found the same hidden configuration inside more than 100 malicious DMG files. One analyzed request actually carried this lure in its parameters:
Download iZotope Ozone Pro ... Plugin Crack
The name isn’t evidence that iZotope itself had anything to do with the campaign. Quite the opposite. Its product name was being borrowed as bait.
The chain used a Bash script to retrieve another stage and included a ClickFix-style prompt designed to convince the victim to paste a malicious command into Terminal. Iru observed payloads including MacSyncStealer and Odyssey.
One detail makes the scale of the thing easier to see. The delivery chain contained an affId parameter. Iru identified it as an affiliate identifier and concluded the campaign was operating as part of a pay-per-install network.
Someone wasn’t just making malware. There was distribution economics behind it.
CloudSEK separately analyzed MacSync, and its findings are the part producers should probably care about more than the malware’s name. The stealer targeted browser credentials and cookies, macOS keychains, cryptocurrency wallets, SSH keys, AWS credentials and Kubernetes configuration files. It also searched Desktop, Documents and Downloads for selected file types.
Then it compressed what it collected, uploaded the archive and deleted the local archive after exfiltration.
That’s a very different proposition from somebody borrowing your CPU to mine Monero.
Now the machine itself is the inventory.
The thing actually worth stealing
For a producer, the plugin may not even be the most valuable thing on the computer.
The unfinished work is.
Late last month, Ariana Grande filed a lawsuit in Los Angeles County Superior Court against unidentified defendants she alleges spent years obtaining unreleased music, photos and other private material through people in her professional circle.
The allegations matter here because of the entry points. According to the complaint, credentials for a photographer’s Dropbox account were obtained in 2019. In 2020, the mobile device of a producer who had worked with Grande was allegedly hacked. The complaint says still-in-production masters, demos and recording-session footage were taken.
Then came phishing.
In January and February 2024, the complaint alleges that attackers created a Gmail account and a lookalike domain impersonating a photographer, then used them to convince that photographer’s digital technician to hand over private material. Grande alleges that 45 unreleased songs were hacked, stolen and leaked in 2023 alone. The complaint also says stolen material was sold using services including PayPal and Cash App before purchasers redistributed it.
Those are allegations. The defendants haven’t been identified and the claims haven’t been adjudicated.
Nothing in the complaint says a malicious music plugin was involved. These are not the same attack.
What connects them is the topology.
In the incidents Grande describes, the access points weren’t some imaginary vault labeled ARIANA GRANDE MASTERS. They were collaborators. A photographer. A producer. A technician. The people already close enough to the work to have it.
Anyone who has ever received stems before release, held a vocal under NDA or opened someone else’s unfinished project should recognize the shape of that immediately.
Your studio can contain somebody else’s secrets too.
Grande had already put her frustration with leaks rather less clinically in 2024. Talking with Zach Sang about leaked material from her sessions, she addressed the people responsible:
“I’ll see you in jail, literally.”
Fair enough.
Piracy isn’t the whole variable
It would be easy to turn all of this into a lecture about cracked plugins. I’m not interested in doing that.
For the record, every plugin and piece of production software I run is paid for in full. That isn’t a flex, and it isn’t a judgment of anyone who has made different choices under real budget pressure. I mention it only because provenance is easier to reason about when you can trace each install back to a receipt and an official download.
There’s a more useful distinction.
On July 29, Tomislav Zlatic released VATRA, the first premium plugin from his Flame Sound label. According to Zlatic, VATRA shipped without copy protection. No activation server, no license manager, no keys.
Roughly two days after launch, an unauthorized copy was already circulating.
There was no protection layer to defeat first.
That’s useful because it separates two things that tend to get collapsed into one argument:
Piracy is a licensing problem. Provenance is a security problem.
I couldn’t find a technical teardown of the unauthorized VATRA copy, so I’m not going to imply it contained anything malicious. There’s no evidence I found that it did.
The point is simpler. Once software leaves the developer’s distribution path, the name on the file isn’t proof of what is inside it.
The same pattern extends far beyond audio software. Kaspersky documented the Stealka infostealer in late 2025 spreading through game mods, cheats and software cracks. One sample masqueraded as a Microsoft Visio crack. The malware targeted data from 115 browser extensions and 80 cryptocurrency wallet applications.
In February 2026, Kaspersky published research on RenEngine, a loader distributed through pirated games and professional software. Researchers found dozens of websites pushing the loader through cracked software, including CorelDRAW. Earlier RenEngine infections delivered Lumma Stealer. More recent chains delivered ACR Stealer, with Vidar also observed.
Neither campaign specifically targeted music producers.
That’s exactly why I care about them.
The producer looking for one missing plugin at 1 AM isn’t living in a special music-industry threat model. They’re downloading executable software from the same internet everyone else is.
Twenty minutes, not a lecture
I’d normally put a listening experiment here.
Not this time.
Do an inventory instead. Open the locations your DAW scans for plugins and, for each plugin you actually use, answer one question:
Where did this copy come from?
Not whether you paid for it. Where it came from.
The vendor’s installer? An official package manager? A developer you know? An old drive? A download folder from three machines ago? Some archive whose origin you honestly don’t remember?
The ones you can’t source are the list.
Don’t panic. Don’t start deleting random files in the middle of active projects either. Just know what they are.
Then look one layer outward. Where do your unfinished projects live? Where are the stems people have trusted you with? What gets synchronized to cloud storage? Which old backups still exist? Who can reach them?
Finally, check the accounts around the work: your distributor, cloud storage, email and collaboration tools. Unique passwords. MFA or passkeys where they’re available. No reused credentials just because all of this feels less consequential than a bank account.
It isn’t.
Twenty minutes.
Maybe longer if the backup situation has become archaeology.
The quiet scan
There is one uncomfortable ending to this.
You can’t prove a plugin is trustworthy just because an antivirus scan is quiet.
The 2024 VST proof-of-concept author reported low detection rates for the malicious VST samples they tested and argued that many security products appeared not to inspect the format closely. That’s one researcher’s observation, not evidence that every security product misses malicious plugins.
From my side of the fence, though, I’ve seen enough security tooling over the years to be skeptical of the comfort it sells. Some of it is excellent. Some of it is expensive snake oil with a dashboard. And a lot of the weaker stuff can be bypassed more easily than the marketing would have you believe. A clean scan is useful evidence, but it’s not the same thing as knowing the file is safe.
But the larger principle doesn’t need that claim.
A clean scan is evidence. It isn’t provenance.
Knowing where the software came from is a different question.
So the inventory isn’t a magic fix. It’s just the part you can actually see.
A plugin solved a problem in the mix, so you kept it. Six months later it became part of the furniture. Three years later nobody remembers where the installer came from.
That’s normal studio entropy.
It also happens to be an attack surface.
Everything in that folder doesn’t run all the time. But everything executable in there can run when the host loads it.
That’s enough reason to know what you put there.
Resources
VST 3 Plug-in Format Structure - Steinberg’s official documentation for the VST3 bundle and executable-module structure on Windows and macOS.
VST Audio Plug-ins for Initial Access and Persistence - infosecnoodle, February 17, 2024. The Ableton/VST3 proof of concept covering command execution, plugin initialization and the
AbletonPushCpl.exepersistence demonstration.LoudMiner: Cross-platform mining in cracked VST software - ESET Research, June 20, 2019. Documents LoudMiner, the 137 VST-related applications found on one distribution site and its QEMU/VirtualBox architecture.
macOS Malware Analysis: Music Plugin DMG Loader - Iru, February 19, 2026. Primary analysis of the 100-plus malicious music-software DMGs, Ozone-themed lure, ClickFix component, MacSyncStealer/Odyssey delivery and pay-per-install affiliate identifier.
MacSync Stealer: SEO Poisoning and ClickFix-Based macOS Malware Delivery Chain - CloudSEK, March 18, 2026. Detailed analysis of MacSync’s credential, keychain, SSH, cloud-configuration and document theft plus its exfiltration process.
Ariana Grande sues alleged hackers over unreleased music leaks - ABC News, July 27, 2026. Reporting based on the complaint filed in Los Angeles County Superior Court, including the alleged 2019, 2020 and 2024 intrusion timeline.
Ariana Grande Calls Out Hackers After Unreleased Songs Leaked Online - People, February 27, 2024. Source for Grande’s Zach Sang Show remarks about the leaked material.
My first plugin was pirated in 48 hours. Here’s why it still has no copy protection. - Tomislav Zlatic, August 5, 2026. First-person account of VATRA’s no-copy-protection release and the unauthorized copy appearing roughly two days later.
The Stealka stealer hijacks accounts and steals crypto while masquerading as pirated software - Kaspersky, December 18, 2025. Documents Stealka’s distribution through cracks, cheats and mods and its targeting of browser extensions and cryptocurrency wallets.
Kaspersky identifies RenEngine loader distributed through pirated games and software - Kaspersky, February 23, 2026. Documents RenEngine distribution through dozens of pirated-software sites and the Lumma, ACR Stealer and Vidar payloads.

