Your Employees Logged In Without Issue; Attackers Logged In Too.
Brief
Five Chrome extensions targeting Workday, NetSuite, and SAP SuccessFactors were caught stealing session cookies every 60 seconds and shipping them to attacker servers. No passwords needed. No MFA challenged. This is what credential monitoring misses, and what cookie monitoring catches.
In January 2026, cybersecurity firm Socket disclosed the discovery of five malicious Chrome extensions on the Chrome Web Store, each masquerading as productivity or security tools for enterprise HR and ERP platforms. The targets were specific: Workday, NetSuite, and SAP SuccessFactors, three of the most widely deployed enterprise platforms in the world.
The technique was precise. The extensions extracted authentication session cookies named ‘__session’ for each targeted domain on a 60-second loop, exfiltrating them continuously to command-and-control servers.
