Skip to main content

Tag: malicious extensions

4 articles

Laptop screen on a desk in a home office with a blurred cityscape background.

Malicious Extensions Target Chrome, Edge Users With Crypto-Draining Code

Beware: malicious Chrome extensions have been discovered that can secretly drain your cryptocurrency wallet! Security researchers uncovered a sneaky campaign that uses 19 extensions to steal wallet secrets and drain crypto funds.

Analyst 207
Laptop with Chrome browser open on desk beside smartphone and notebook.

Fake Chrome VPN Extensions Expose Users to Proxy Routing Risks

Beware of Chrome VPN extensions that may be putting your online security at risk: over 737 extensions impersonated popular VPN and proxy services, secretly routing users' traffic through unsecured SOCKS5 proxies. This exposed users to potential data breaches and surveillance, as their browsing activity was intercepted by a single, unknown provider.

Analyst 207
Developer workstation with laptop and monitor on a clean desk, code editor open on screen.

Open VSX Eradicates Malicious Extensions Exfiltrating Developer Data

A shocking discovery by Manifold Security revealed that 77 malicious extensions on Open VSX were secretly siphoning off sensitive data from developers' machines between July 26 and August 1, 2026. These fake extensions, masquerading as legitimate tools, were swiftly removed by Open VSX on August 3, 2026.

Analyst 207
Chrome browser window on laptop showing Claude extension interface with workflow process.

Claude Extension Flaw Exposes AI Actions to Malicious Extensions

A security researcher discovered a vulnerability in Anthropic's Claude browser extension that allows malicious Chrome extensions to trick it into performing predefined AI actions on connected services like Gmail and Google Docs. This flaw could have serious consequences, as it only requires a simple simulated click to launch built-in workflows.

Analyst 207