Trusted Chrome, Edge extensions weaponized in supply chain campaign
Summary
Attackers have weaponized legitimate browser extensions for Chrome and Edge by acquiring them from publishers and injecting malicious code through updates. This campaign affected 19 extensions, some with tens of thousands of users, and enabled the theft of cryptocurrency and sensitive user data.
IFF Assessment
This article details a sophisticated supply chain attack that compromises trusted software, posing a significant risk to end-users and organizations by enabling data theft and cryptocurrency loss.
Defender Context
This campaign highlights the risks associated with browser extensions, especially those acquired by new owners. Defenders should monitor extension permissions closely, educate users about the dangers of relying solely on initial trust, and consider implementing browser extension management policies to vet and control approved extensions.