So a few weeks back my sister told me my skype account was spamming her. I never use skype, and didn't know my password but I used my recovery email to change the password and called it good. Today I got an email from skype saying my account was suspended for spam until I changed my password (not phishing email, not even hyperlinks in the message). Thing is my password had not changed, meaning one of two things: skype itself has a vulnerability or I my puter was hacked.
I checked my recovery email, even though my password didn't change, and there were no unusual logins. Skype doesn't provide login ip information. I hadn't logged in since originally changing my password - once to the web client and once to the software client. My computer is arch linux using gnome so it hasn't been easily compromised. The skype client is installed from the official repository and is more legitimate than the windows install imo (no pressure to install adware). I also don't reuse passwords.
I don't use skype so don't really care, but it bothers me that it happened. To my knowlegde no other accounts have been compromised. I have a hard time believing someone got shell access to my computer, it could be possible, but I'd go for my bank account or paypal account or take advantage of the internet connection. Obviously my skype account has been targetted if it was logged into even after changing my password. How can I ensure this isn't on my end? I recently formatted my computer (same setup before) and previously should have been running ufw only allowing http/s same with my fresh install, but it hasn't been working quite right and I haven't fixed it. Nothing is being forwarded from the router.