#browser-extensions
13 stories taggedbrowser-extensions.

The Week's Security Mess: Why Did Any of This Work in the First Place?
From greedy browser extensions to phishing pages built inside trusted services, this week's incidents share one uncomfortable answer.

Malicious Twitch Extension Siphoned Login Tokens From 31,000 Viewers
A browser add-on marketed as a Twitch viewer tool quietly forwarded OAuth tokens to servers linked to a Russian bot-for-hire service.

PEEP: The Fake Bookmarks Extension That Turns Chrome Into a Backdoor
Researchers have detailed a post-exploitation toolkit that quietly slips into Chrome and Edge profiles by forging the browser's own trust files.

Nineteen Browser Extensions Caught Emptying Crypto Wallets
Researchers found 18 Chrome add-ons and one Edge add-on that quietly stole wallet keys and drained funds, in a campaign that may have run for months.

Fake Firefox Wallet Extensions Drain Crypto From Unwary Users
Researchers at Socket found 40 Firefox add-ons impersonating OKX, Rabby, TronLink and other crypto wallet brands, part of a wider 77-extension operation they call Offside Wallet Theft Factory.

737 Fake VPN Extensions in Chrome Store Quietly Hijacked Browsers
The free browser add-ons promised to unblock websites for Russian speakers. Instead they routed every page a user visited through servers the operators controlled.

The Week Malware Wore a Friendly Face: Fake Extensions, Poisoned Packages and an Image That Talked to an AI
The payload wasn't the story this week. The disguise was.

KU Leuven Researchers Find 85 Browser Crypto Wallets Leak User Data
Academic study says the way popular wallet extensions talk to websites lets outsiders link separate crypto addresses to the same person.

A Bug in the Claude for Chrome Extension Has Survived Eight Fixes and Still Leaks Your Gmail
A flaw nicknamed 'ClaudeBleed' lets other browser extensions quietly read your email and calendar. After eight attempted patches, it apparently still works.

Chrome and Edge Yank ModHeader Extension After Hidden History Collector Found
The browser add-on had 1.6 million users. A dormant tracker sat inside its official store version, though no evidence suggests it ever ran.

Opera GX Bug Let Any Website Silently Install a Data-Stealing Add-On
One page visit was enough to rebuild a signed-in user's Gmail address. Opera has patched the flaw.

Silent Swap: Unsigned Installers Drop Fake Chromium Extensions That Hijack Crypto Transactions
McAfee Labs documents a clipper campaign using .NET and Golang loaders to sideload a malicious browser extension that rewrites wallet addresses at send time.

Microsoft Pulls 119 Edge Extensions Tied to 'StegoAd' Steganography Campaign
The add-ons concealed payloads in image and font files and activated days after install. Microsoft attributes the activity to a single actor operating since 2021.