<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dormant-Malware on CuraSec</title><link>https://curasec.metacog.co.kr/tags/dormant-malware/</link><description>Recent content in Dormant-Malware on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 14 Jul 2026 12:08:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/dormant-malware/index.xml" rel="self" type="application/rss+xml"/><item><title>ModHeader Extension Pulled After Dormant Browser-History Collector Discovered</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-google-and-microsoft-pull-modheader-with-1-6-million-install/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-google-and-microsoft-pull-modheader-with-1-6-million-install/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> ModHeader is widely used by engineers for API and header debugging — remove it from all developer and CI browsers now and replace with a vetted alternative; dormant or not, undisclosed collection code in a tool with store-level trust is a supply-chain red flag.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No active exploitation or IOCs to sweep for, but this is a prompt to audit the browser extension inventory across developer workstations and establish an approved-extension policy or detection for unapproved extension installs.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> No data was collected and both stores have already pulled the extension, so no breach disclosure or vendor inquiry is warranted; useful data point on browser-extension supply-chain risk when building or updating software-inventory and vendor-vetting policies.&lt;/li>
&lt;/ul></description></item></channel></rss>