Announcements

Help Wizard

Step 1

NEXT STEP

Spotify Connect Exploit - Spotiamb 0.2.1. - hijacks user accounts to play songs.

Solved!

Spotify Connect Exploit - Spotiamb 0.2.1. - hijacks user accounts to play songs.

Hi all,

Just wanting to draw attention to this. It appears that there is an exploit for Spotify Connect which uses the Spotiamb 0.2.1 extension to hijack user accounts and play a set list of songs. Affected users will see "Spotiamb 0.2.1" appear as an available Spotify Connect device. The result is that their account will, multiple times throughout a day at random intervals, play albums by these two artists, amongst others:

 

Dungeonsd: https://open.spotify.com/album/66xm00as0QlKB2dOE6fUpH

 

Tony Oldam: https://open.spotify.com/album/3m0eumQjUDrLyAwJmkFMpi

 

These tracks will interrupt anything the user is currently playing. 

 

Other users are experiencing the exact same behaviour

https://community.spotify.com/t5/Help-Desktop-Linux-Windows-Web/Random-unsolicited-song-hijacks-play...

 

https://community.spotify.com/t5/Help-Accounts-and-Subscriptions/Spotify-hacked-by-a-pro/m-p/1178797

 

Could a member of the Spotify team please comment on this? It is somewhat concerning that there appears to be an unaddressed explit capable of making user accounts play any tracks they wish.

 

Many thanks.

 

 

Reply
157 Replies

Be sure to reset the passwords of both Spotify and Facebook before forcing
logouts on all devices - that is what worked for me. Not seen Spotiamb
since.

Okay, it seems that I have fixed the problem for myself. I have been listening to spotify for the entire day without the Spotiamb device appearing. 

1. I removed Spotify on all my devices (windows and android phone) 

2. Reset the pasword and signed out of all my devices (I had no FB sign in)

3. Removed all the apps on the website (see attachment)

4. Reinstalled on laptop (new download from the official website) and it seems to work. 

Knipsel.JPG

I've got the same problem today. I've done all the suggestitons and nothing has worked. The music keeps pausing randominly. Can anyone please help?

 

 

 

Spotiamb 0.2.1.png

 

I'm running into this same thing. Taken all advice in this thread, including resetting Facebook password, but still I'm getting random Spotiamb connections logging in and playing music. I don't appear to have any devices on my account listed either, which seems odd to me. I submitted a ticket (# 07310404) but no word back yet. The fact that I reset me password and logged out of all devices yet the Spotiamb connection went live again within a half hour is concerning to say the least.

Yeah, just had this very issue occur with me too. Only mine played "Across My Mind - Mark Eternal". This is 100% some kind of exploit because I have never used another device or made any changes to my account in the last few months. With as wide spread as this is, and the amount of people reporting it... I would really hope that Spotify takes this seriously and looks into it. I did notice a strange app on my app list that I've since removed, will write back if it pops up again, offline devices was empty though. 

Same thing happened to me..... This is something that's been going on since 2015. Spotify assured me that my financial information was not leaked but I have serious doubts and will be monitering everything very closely.... But if something like this ever happens again, I will be forced to find another music streaming service. Get on it Spotify. Remove this feature. It has caused more pain than suffering

It happens to me today too... Please Spotify help us!

They've assured me that my bank information was not visible to the hackers. And we went through steps to safely give control back to me. Which was good on them but this should have never happened in the first place..... And if you're a Sprint user, you might be getting a free subscription to Tidal very soon. That being said, I've cancelled my spotify subscription

Same problem, started occuring yesterday. Noticed it on my tablet while driving.
The problem kept going on my laptop however.

 

  • Your platform and operating system (Mac, Windows, iPhone etc.).
    Android + Windows 10.
  • The version of Spotify you're running (you'll find this under About Spotify in the app's settings).
    1.0.45.186.g3b5036d6(windows) 7.2.0.1250 armV7 (Android)
  • Is this happening over WiFi? 3G/4G? Both?
    Both. Problem started when using 3g or 4g.
  • How much storage you have left on your device?
    500~gb. PC, 30GB Android.
  • A full description of the issue, with as much detail as possible.
    Music pauses every 5~20 minutes, and a device is available (Spotiamb 0.2.1)
  • How long you've had this issue.
    2 days.
  • What actions led to it happening. 
    No clue, using spotify I guess?
  • Does the issue appear on any other devices that you use Spotify on?
    Yes. Android/Windows.

    Steps to prevent it:
    Removed all App access to my account.
    Looked at where my account was being used (Only the actually pc's location was listed, tablet was offline when looking. The Spotiamb was not listed, but was listed in the pc program)

The same thing happened to me.

It started out this morning when I was playing through a Chromecast.

I paused/stoped the music on my tablet because I was going out.

When I came back home the music was on, playing the same playlist I was previously listening to. I figured I must have accidetaly pressed next song or something instead of pause - and not hearing that the music started.

 

Then it happend once more a couple of hours later, still playing from my Chromecast device and the same playlist as before.

This is when I noticed Spotiamb 0.2.1 in the device list.

 

I revoked all App access from my account and logged out all devices through the link on spotify.com

Logged in again on 2 devices only (Android Tablet and Phone).

An hour later it started playing again, this time through the tablet and some random artist that I've definitely never listed to before.

 

Now I've logged out all devices, changed password and then logged out all devices again.

I hope that'll do the trick.

i dont know if this is true, but my problem/hijack happen just after i connect my Spotify with Shazam. i dont know if Shazam is the reason, but just in case

 

1. i went to Apps and removed all app from there

2. changed my Spotify password

3. when to offline devices and remove all devices that i dont use anymore

4. signout from everywhere

doing this fixed my problem

I got hijacked for the first time 10 minutes ago... I guess I'm stuck with that for the rest of my life?

Marked as solution

yochimo135, the actions I took earlier this week has worked good for me so far.
As described above;
1. Revoke all App access
2. Logout all devices
3. Change password
4. Logout all devices

I'm not sure which action (or combination) that solves the issue, but I made them all to be sure.

I wonder how this came to happen, if it's a brute force, exploit or some kind of leak.
As far as I know, the combination of username/password I have for Spotify is unique and therefore couldn't have been leaked from some other dump.

I just noticed that Spotiamb had accessed my account this morning, but now that I think back it's probably been happening for about a week.  I'd never thought to check the connceted devices list.  

 

Just followed the same steps as Chopp, will update in a day or so to see if those steps worked.

No further interuptions.  Seems that following those steps worked!  I'm not sure if it'll work in all cases, but for mine it seemed to have sufficed.  

I followed the instructions of changing my password and removing Spotiamb and I haven't had any issues recently. Is there anyway my CC information will be compromised from this?

I have been hijacked as well. Needless to say this is unacceptable. I'm trying to change my password. But I sign in with a Facebook and that's the only way I know how to sign in to Spotify. I changed my Facebook password and I'm still being hijacked. How can I make a new sign in with my email and a new password?

I had the same problem too.

 

I attempted to contact Spotify about it through their chat help. I waited over an hour and a half for a specialist but could not get anyone to help me. I talked to three different people who all tried to transfer me to this "specialist" and confirmed they were available before they patched me through but nothing got across 😞 

 

At this point, I have disconnected all my devices twice and also changed my password. I just changed my password so hopefully that will help. 

 

I have had Spotify for three years and am the biggest advocate but this is frustrating not being able to get anyone to help 😞

 

 

 

 

I don't understand how Spotify is completely absent from this thread. This is embarrassing for any software developer. Any software where unauthorized users can bypass authentication and gain unauthorized software access is bad code. Spotify, where are you? Where are the patches? There are clearly vulnerabilities within your code allowing this spotiamb exploit to thrive. I am also a Spotify veteran and would hate to migrate to a more secure platform, like Apple Music. Your absence in this thread signifies a lack of care for basic security principles, leaving paying users nervous for your next software exploit you leave open. I am also having the issue. Securely changing passwords does not resolve the issue. Removing external app access will probably fix the problem. Embarrassing, Spotify.

Suggested posts