Browser Add-Ons, AI Chat Links and In-Memory macOS Attacks: A Week the Internet Worked As Designed
Shady extensions, weaponised Claude conversations, fileless macOS intrusions and cloud agents turned into shells dominated the criminal feeds this week.

The internet didn't break this week. Attackers just used it the way the manuals describe.
Search traffic got siphoned through browser extensions that looked legitimate in the Chrome and Edge stores. The add-ons rewrote query results, redirected affiliate clicks, and in several cases shipped clipboard-stealing logic alongside the advertised features. Victims ranged from retail consumers to corporate endpoints where the extensions had been sideloaded without security review.
AI chat platforms got pulled into the delivery chain. Crooks abused shareable conversation links on Anthropic's Claude to host lure pages and stage second-stage payloads, exploiting the trust users place in a vendor-hosted URL. The link itself is innocuous. What sits on the other side isn't.
On macOS, responders flagged a fresh wave of in-memory intrusions that leave almost no disk artefacts. Initial access came from cracked-app trojans and ClickFix-style social engineering. Once running, the loaders pulled stagers directly into memory and queried iCloud Keychain, browser cookies and crypto wallets. Forensics teams describe the cleanup as expensive and the detections as thin.
Cloud agents got their turn too. Helper bots wired into enterprise SaaS — the kind that read tickets, draft replies, and execute API calls — were coaxed into running attacker instructions hidden inside the documents they were told to process. Prompt injection stops being theoretical when the agent has a write-scope token.
The npm registry surfaced another supply-chain cluster, this one tagged NastyC2. The packages dropped a lightweight command-and-control beacon on install via postinstall scripts. Maintainers pulled the offending versions, but typosquats remained live for days. Developer machines and CI runners are the assumed targets.
Device-code phishing continued its run against Microsoft 365 tenants. Operators send a victim a legitimate Microsoft login URL paired with a code they generated, harvesting tokens without ever standing up a fake portal. Conditional access policies that don't restrict device-code flows are doing the attackers' work for them. Guidance on hardening that flow sits in Microsoft's identity platform docs.
Edge gear stayed on the board. Exposed firewalls, VPN concentrators and file-transfer appliances kept showing up in initial-access broker listings, with asking prices tracking the size of the downstream network rather than the bug itself.
A separate strand: cash courier scams aimed at elderly victims, increasingly coordinated through the same Telegram channels that host carding and SIM-swap crews. The crossover between cyber-enabled fraud and physical pickup logistics is no longer novel.
No single incident defined the week. The pattern did. Trusted surfaces — stores, chat links, agents, registries — kept getting used as carriers, and defenders kept paying the cost of treating them as safe by default.



