
The extension that opens whatever tab its server tells it to
A malicious browser extension can let a remote server open any tab — an ad, a redirect, a fake login. How it works, and how to check and remove them fast.
10 articles found

A malicious browser extension can let a remote server open any tab — an ad, a redirect, a fake login. How it works, and how to check and remove them fast.

The GlassWorm takedown by CrowdStrike and Google won't uninstall anything. Here's how to check for malicious browser extensions still sitting in your browser.

Socket found 108 Chrome extensions routing logins and live Telegram sessions to a single server. Here's how the campaign worked and how to check your own.

A fake uBlock Origin clone crashed Chrome on purpose, then tricked users into running malware. Here's how to spot the CrashFix trap and check your extensions.
GhostPoster hid malware inside extension icon images for up to five years across Chrome, Firefox, and Edge. Here's how steganography works and what to check.
A sideloaded browser extension is how UNC6692's SNOWBELT runs inside headless Edge, skipping Web Store review entirely. Here's how to detect it in your org.
GlassWorm malware compromised 72+ Open VSX IDE extensions to drop a Chrome infostealer that steals session cookies via Solana C2. Here's what to check today.
ShadyPanda ran 145 malicious browser extensions on Chrome and Edge for 6 years — from affiliate fraud to keylogging spyware, 4.3M installs. How to check yours.
A zero-permission extension can still drop malware: LayerX Labs showed any extension can silently backdoor your downloads. How to check and stay safe.
17 malicious sleeper extensions found across Firefox, Chrome, and Edge with 840K downloads. They hid malware in images for up to 5 years undetected.