
Malware that arrives in the update, not the install: how to check your extensions
A Chrome extension pulled in January is back — and shipped its payload two weeks after a clean release. How update-time malware works, and how to check yours.
31 articles found

A Chrome extension pulled in January is back — and shipped its payload two weeks after a clean release. How update-time malware works, and how to check yours.

Cookie extensions touch your session tokens and every site you visit. I compared Cookie-Editor, Cookie AutoDelete and the banner blockers on who owns them.

Socket found 737 fake VPN extensions routing Chrome browser traffic through one operator's SOCKS5 proxies. Here's how to check yours and reset the damage.

Edgecution abused native messaging to run a Python backdoor outside Edge's sandbox — from a headless browser you'd never see. How to check your own machine.

The downloads permission lets an extension read every file you've downloaded, write new ones, and hide the download UI. Here's what it allows and how to check.

Infostealers now bypass Chrome's App-Bound Encryption to raid crypto wallet and password manager extensions. Here's how to check yours and lock them down.

A malicious browser extension can let a remote server open any tab — an ad, a redirect, a fake login. How it works, and how to check and remove them fast.

The GlassWorm takedown by CrowdStrike and Google won't uninstall anything. Here's how to check for malicious browser extensions still sitting in your browser.

Socket found 108 Chrome extensions routing logins and live Telegram sessions to a single server. Here's how the campaign worked and how to check your own.

Session cookie theft lets attackers skip your login and 2FA. Chrome 146's DBSC binds sessions to your device — but here's the gap extensions still exploit.

Two-thirds of Edge extensions and half of Firefox add-ons sit abandoned — no security update in a year. Why stale extensions are risky and how to check yours.

Everyone said Chrome's Manifest V2 deadline would kill ad blockers. Here's what the sunset actually stranded — and why Firefox is now the MV2 refuge.

A fake uBlock Origin clone crashed Chrome on purpose, then tricked users into running malware. Here's how to spot the CrashFix trap and check your extensions.
GhostPoster hid malware inside extension icon images for up to five years across Chrome, Firefox, and Edge. Here's how steganography works and what to check.

Google accidentally exposed an unfixed Chromium service worker flaw that keeps background scripts running after you close the browser. Here's how to stay safe.

A Chrome extension's leaked OAuth tokens pivoted into Vercel's systems. Here's how to audit the extension OAuth grants in your work Google account.

Any zero-permission extension can hijack Claude's AI session and exfiltrate your Gmail or GitHub data. Here's how ClaudeBleed works and how to protect yourself.
A sideloaded browser extension is how UNC6692's SNOWBELT runs inside headless Edge, skipping Web Store review entirely. Here's how to detect it in your org.
Chrome extension privilege escalation is real: CVE-2026-0628 let extensions with basic permissions reach your camera, mic, and files via the Gemini panel.
GlassWorm malware compromised 72+ Open VSX IDE extensions to drop a Chrome infostealer that steals session cookies via Solana C2. Here's what to check today.
ShadyPanda ran 145 malicious browser extensions on Chrome and Edge for 6 years — from affiliate fraud to keylogging spyware, 4.3M installs. How to check yours.
18 Chrome, Firefox, and Edge meeting extensions with 2.2M installs secretly harvested corporate meeting data. Here's what they did and how to check yours.
Stanley MaaS sold guaranteed Chrome Web Store placement for $6,000. Here's how phishing extensions slip past Google's review — and how to protect yourself.
The real Proton VPN extension is a standalone browser VPN — with broad permissions by design. Here's what it actually requests and how to spot the fakes.
A zero-permission extension can still drop malware: LayerX Labs showed any extension can silently backdoor your downloads. How to check and stay safe.
QuickLens got hijacked via an extension ownership transfer to push ClickFix and crypto-stealing malware. Here's how to check your own add-ons are still safe.
ETH Zurich broke the zero-knowledge promise in Bitwarden, LastPass, and Dashlane with 25 attacks. See which password manager extensions actually held up best.
Any browser extension can silently inject commands into ChatGPT, Gemini, and Claude. Here's how man-in-the-prompt attacks work and how to keep yourself safe.
Security researchers exposed 300+ malicious Chrome extensions with 37.4M downloads stealing data, credentials, and emails. Here's how to protect yourself.
30 fake AI Chrome extensions caught stealing credentials and Gmail data from 300K users. Here's how to check if you're affected and protect yourself.
17 malicious sleeper extensions found across Firefox, Chrome, and Edge with 840K downloads. They hid malware in images for up to 5 years undetected.