Pale Moon Archive Server Was Hacked
forum.palemoon.org
forum.palemoon.org
> I've ruled out remote FTP access, remote RDP access and execution of insecure software on the VM as potential breach points considering this access was at all times limited to myself only and locked down by IP and with secure, unique password protection.
I'm not so sure that FTP can be so easily ruled out. (This is assuming FTP means FTP and not FTPS or SFTP).
The "unique password" is broadcast in the clear. Anyone watching a connection gets to see it. (They also get to see your username and IP in the clear.)
The IP Authentication mechanism appears to be trivially spoofable thanks to allowing IP-forwarding. Without an actual authentication mechanism for the connection (SSL, SSH in the main alternatives), you can send from one IP, whilst supplying another to the protocol that gets used for auth.
It could be that they've simply checked the FTP server's log files and determined they didn't come in that way?
But yes, I really hope they mean (S)FTP(S) and not FTP.
As to logging, most FTP servers log the forwarded IP and not the connecting IP when you enable forwarding.
So yes, FTP may well be the point of entry.
(Worth noting that a couple minutes looking at the palemoon site still comes up with quite a few security red flags. Like unenforced SSL on download pages, archive.palemoon.org still has no SSL, etc.)