Trusted Chrome and Edge Extensions Weaponized in Supply Chain Cyberattack
Researchers at Socket have uncovered a supply chain campaign where previously legitimate browser extensions for Google Chrome and Microsoft Edge were weaponized into malware. The attackers acquired 5 extensions from their original publishers and created 14 others, initially without malicious code. These extensions were later updated to include malware, affecting users who had installed them when they were considered safe. This tactic exploits the trust users place in established extensions and the difficulty in detecting changes after ownership transfers or software updates. The campaign highlights a significant security problem where an extension's safety can degrade over time, leaving existing users vulnerable without their knowledge. The findings indicate a sophisticated approach to cyberattacks, leveraging the widespread use of browser extensions to gain unauthorized access or distribute malicious software.