CISOOnline

Trusted Chrome, Edge extensions weaponized in supply chain campaign

The campaign was heavily focused on cryptocurrency theft, but its capabilities went further. Socket observed code that captured information typed into web forms and extracted authentication material from active browser sessions. Other modules targeted logged-in social media accounts and collected browser history.

Socket linked the extensions to a broader operation dating to February 2024 based on similarities with activity previously documented by DomainTools. The researchers said the malware’s design allowed attackers to change the payloads delivered to infected browsers over time.

Extensions become supply-chain risks

The campaign shows why companies can no longer treat approval of a browser extension as a one-time security decision, according to Keith Prabhu, founder and CEO of Confidis.
 
“CISOs should treat browser extensions as continuously changing third-party software, not as static productivity tools,” Prabhu said. “Organizations should move from ‘install approval’ to ‘lifecycle assurance’ for browser extensions.”

That means security teams may need to reassess extensions after deployment, particularly when ownership changes or new versions request broader permissions. Changes to code and publisher identity can provide early warning that an extension no longer carries the same risk profile it had when first approved.

Jonathan Ong, senior analyst for managed security services at Omdia, compared the tactic to attacks involving malicious mobile applications, where a clean initial version is used to gain approval before harmful code is introduced in a later update.



Source link