<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Browser-Extensions on CuraSec</title><link>https://curasec.metacog.co.kr/tags/browser-extensions/</link><description>Recent content in Browser-Extensions on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 28 Aug 2026 21:21:40 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/browser-extensions/index.xml" rel="self" type="application/rss+xml"/><item><title>19 Malicious Chrome/Edge Extensions Drain Crypto Wallets</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-19-chrome-and-edge-extensions-found-with-wallet-stealing-and/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-19-chrome-and-edge-extensions-found-with-wallet-stealing-and/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Audit managed Chrome and Edge extension allowlists against the 19 identified malicious extensions (details in the Socket/Hacker News report); enforce an extension allowlisting policy to block unapproved installs in managed browser deployments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Pull endpoint telemetry to hunt for these extension IDs across managed devices; build or tune a detection for novel extension installations that request broad permissions aligned with credential or clipboard access.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A coordinated six-month extension campaign highlights browser add-ons as a persistent supply-chain risk; useful context for reviewing whether your browser governance policy enforces an approved extension allowlist.&lt;/li>
&lt;/ul></description></item><item><title>40 Malicious Firefox Extensions Steal Crypto Wallet Secrets via Web3 Lures</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-40-malicious-firefox-extensions-pose-as-web3-products-to-ste/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-40-malicious-firefox-extensions-pose-as-web3-products-to-ste/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your org uses Web3 tooling or allows browser extensions in managed environments, audit installed Firefox extensions against the 77 flagged add-ons (OKX, Rabby Wallet, TronLink impersonators) and enforce extension allowlisting via policy.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for browser extension installs from unofficial sources in managed endpoints; hunt for any of the 77 flagged extensions identified by Socket in your EDR extension inventory.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>737 fake Chrome VPN extensions route traffic via rogue SOCKS5 proxies</title><link>https://curasec.metacog.co.kr/insights/2026-08-13-hundreds-of-fake-chrome-vpn-extensions-route-traffic-through/</link><pubDate>Thu, 13 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-13-hundreds-of-fake-chrome-vpn-extensions-route-traffic-through/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Audit any corporate-managed Chrome extensions against a blocklist of the 737 identified fakes; establish a policy requiring allowlisted extensions only for managed devices.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build detection for unusual SOCKS5 proxy egress from endpoints, and consider hunting for browser extension IDs associated with this campaign in endpoint telemetry.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Illustrates scale of Chrome Web Store supply-chain risk for enterprise endpoints; useful context for policy decisions around browser extension governance, but no immediate board-level action required.&lt;/li>
&lt;/ul></description></item><item><title>737 Malicious Chrome VPN Extensions Proxy User Traffic via Hidden Infrastructure</title><link>https://curasec.metacog.co.kr/insights/2026-08-13-737-chrome-vpn-extensions-caught-routing-traffic-through-pro/</link><pubDate>Thu, 13 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-13-737-chrome-vpn-extensions-caught-routing-traffic-through-pro/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Extensions impersonating legitimate tools and silently proxying browser traffic is a real enterprise risk if employees install free VPNs on managed Chrome instances. Audit installed extensions across corporate devices and enforce an allowlist policy to block unapproved extensions.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Browser extension-based traffic interception is a useful TTP to understand, but the summary provides no IOCs, C2 infrastructure details, or SIEM/EDR-actionable signals — primarily consumer-targeted with no immediate detection engineering opportunity.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Study: 85 Crypto Wallet Browser Extensions Leak Addresses, Enable Tracking</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-study-of-85-crypto-wallet-extensions-finds-address-leaks-and/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-study-of-85-crypto-wallet-extensions-finds-address-leaks-and/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research exposes a class of extension-level data leakage — wallet extensions correlating addresses and enabling cross-site tracking — worth considering when evaluating browser extension risk in enterprise environments or building wallet-adjacent tooling, but no patch or configuration action is available from this study.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>