There's a strong relationship between the quality of software packaged with a product and the relative importance of software to the maker's product line as a whole. This Energizer example is an extreme point on the graph.
My guess is that whoever made the installer had his computer infected. Not all companies have strict rules about what can be on the computer (or developers choose to not follow them and find ways around their enforcements) and this can be one of the downsides. I can't guess whether they virus-scanned the installation or not because it's quite possible that the trojan was new and not being picked up by scanner when they released the charger.
Comments
How does code like that get in a system from a major corporation?
Is this an outsourcing/supplier issue, or something related to Energizer's own staff?
Wild guess: the software was outsourced to a software house, probably in one of the more "disreputable" countries.
It's a common method of doing it.
There's a strong relationship between the quality of software packaged with a product and the relative importance of software to the maker's product line as a whole. This Energizer example is an extreme point on the graph.
My guess is that whoever made the installer had his computer infected. Not all companies have strict rules about what can be on the computer (or developers choose to not follow them and find ways around their enforcements) and this can be one of the downsides. I can't guess whether they virus-scanned the installation or not because it's quite possible that the trojan was new and not being picked up by scanner when they released the charger.
Ok, I found this analysis by Symantec which makes the whole thing less naive than I originally thought: http://www.symantec.com/connect/fr/blogs/trojan-found-usb-ba...
They indicate a Liu Hong seems to have authored the install package. No indication if he was a Energizer employee or not.