Trusted Chrome, Edge extensions weaponized in supply chain campaign
Brief
Attackers have turned previously legitimate browser extensions into malware after acquiring them from legitimate publishers, potentially allowing malicious updates to reach users who had installed the software when it was still safe, researchers at Socket have found.
The campaign involved 19 extensions for Google Chrome and Microsoft Edge. Five had originally been developed by legitimate publishers and were later acquired by the attackers, according to Socket. The other 14 were created by the threat actor but did not contain malware when first released.
The findings highlight a security problem that can be difficult for users and companies to spot. An extension that appears safe when first installed can change after an ownership transfer or software update, while existing users may have little reason to revisit an earlier decision to trust it.
