[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDb1UVorhyLcD-c1axvmUZb2A0MfBYm4knFaLnvdOARo":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"f0a6e92a-d32b-4baa-a089-5ed657a7030e","hijacked-browser-extensions-weaponized-to-steal-crypto-wallets-and-credentials","9137fcaf-4b8e-43b7-95d5-2a5f84eb4b22","Hijacked Browser Extensions Weaponized to Steal Crypto Wallets and Credentials","Threat actors acquired legitimate, trusted browser extensions with large existing user bases and silently injected malicious code, exploiting browser auto-update mechanisms to push payloads to tens of thousands of unsuspecting users. This is a classic software supply chain attack: users trusted the extension's established reputation, while the browser's own update infrastructure became the delivery vehicle for credential harvesting and cryptocurrency theft. The use of advanced evasion techniques like CSP stripping and WebSocket C2 communication made detection particularly difficult for average users and even many security tools. This incident highlights that third-party software components — including browser extensions — represent a significant and often overlooked supply chain risk.","**Immediate actions:**\n- Audit and remove any browser extensions not explicitly approved by your IT or security team from all managed endpoints.\n- Block or restrict browser extension installations via enterprise policy (e.g., Chrome Enterprise or Edge Group Policy) to an allowlist of vetted extensions.\n\n**Long-term improvements:**\n- Establish a formal browser extension vetting and approval process that includes periodic re-reviews, since ownership and code can change after initial approval.\n- Monitor extension permissions and auto-update behavior using endpoint management tools, flagging any extensions that request sensitive permissions like clipboard access, cookie access, or network interception.\n- Treat browser extensions as third-party software components within your supply chain risk management program.\n\n**Detection measures:**\n- Deploy browser security solutions or EDR tools capable of detecting anomalous extension behavior such as unexpected WebSocket connections or DOM manipulation.\n- Enable and review browser and endpoint telemetry for signs of session hijacking, credential exfiltration, or unauthorized cryptocurrency wallet access.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management","NIST CSF DE.CM-7: Monitoring for Unauthorized Software","NIST AC-3: Access Enforcement","NIST SI-7: Software, Firmware, and Information Integrity","GDPR Article 32: Security of Processing (credential\u002Fsession data exposure)","ITIL: Change and Release Management (vetting third-party software updates)","published","2026-08-27T21:20:20.007285+00:00","2026-08-27T21:20:19.72+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fchrome-edge-extension-wallet-drainer?utm_medium=feed","19-chrome-and-edge-extensions-deliver-a-wallet-drainer-and-credential-stealing-p-e99425","19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[48],{"id":49,"date":50,"edition":51,"title":52,"audio_url":53},"4c9cf0a4-ca83-4f11-a929-8b38680d39ad","2026-08-28","morning","ThreatNoir Morning Brief — August 28","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-28\u002Fthreatnoir-morning-brief-2026-08-28.mp3"]