[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCrHXnOOMTWQxGlBGOOzL9faKjMkFFBth_MVh0UhUjGY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"77f7d43e-d7b3-4c5b-9d44-fdfc16c084f4","popular-chrome-extension-hides-remote-code-execution-backdoor-in-10m-installs","b2e7c4d6-6c33-4257-9218-4a015e38415d","Popular Chrome Extension Hides Remote Code Execution Backdoor in 10M+ Installs","The 'Adblock for YouTube' Chrome extension harbors dormant script injection capability that allows its remote server to push arbitrary JavaScript to any website a user visits — all without triggering an extension update or Chrome Web Store review. This is a classic software supply chain attack vector: users trust a highly-rated, 'Featured' extension without understanding the breadth of permissions it silently holds. The extension's prior associations with ad-injection malware networks and its mismatch between claimed functionality (YouTube-only) and actual permissions (all websites) are red flags that went undetected by millions of users. This matters because a single server-side configuration change by the extension's operator — or a malicious actor who compromises that operator — could instantly weaponize 10 million browsers for credential theft, session hijacking, or data exfiltration at scale.","**Immediate actions:**\n- Audit and remove browser extensions with excessive permissions that exceed their stated functionality from all managed devices.\n- Block or flag the 'Adblock for YouTube' extension (Chrome Web Store ID) via enterprise browser management policies until it is confirmed safe.\n- Review browser extension allowlists and enforce a deny-by-default extension policy across your organization.\n\n**Long-term improvements:**\n- Implement a formal browser extension vetting process that evaluates requested permissions, developer history, and network call behavior before approving extensions for enterprise use.\n- Establish a maintained allowlist of approved extensions and use tools like Google Admin Console or equivalent MDM solutions to enforce it.\n- Treat browser extensions as third-party software in your supply chain risk management program, requiring periodic re-evaluation.\n\n**Detection measures:**\n- Deploy endpoint or browser telemetry solutions (e.g., Island Enterprise Browser, Chrome Enterprise reporting) to monitor and alert on extension behavior such as broad host permissions or unexpected remote script fetching.\n- Monitor network traffic from endpoints for suspicious outbound requests to extension-related remote configuration servers.\n- Subscribe to threat intelligence feeds that track malicious or high-risk browser extensions to receive timely warnings about newly identified threats.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST CSF ID.SC-2: Suppliers and third-party partners are identified and prioritized","NIST CSF PR.IP-1: Baseline configuration of systems is established and maintained","GDPR Article 32: Security of processing (risk of unauthorized data access via compromised extensions)","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 CM-7: Least Functionality (restrict unauthorized software\u002Fplugins)","published","2026-06-25T16:21:10.474835+00:00","2026-06-25T16:21:10.129+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002Fchrome-ad-blocker-with-10m-installs.html","chrome-ad-blocker-with-10m-installs-found-with-dormant-script-injection-capabili-7670c7","Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[48],{"id":49,"date":50,"edition":51,"title":52,"audio_url":53},"e343fcbd-c5e9-4c07-8654-903ff82126dd","2026-06-26","morning","ThreatNoir Morning Brief — June 26","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-26\u002Fthreatnoir-morning-brief-2026-06-26.mp3"]