logo

5 Malicious Chrome Extensions Attacking Enterprise HR and ERP Platforms for Complete Takeover

ID: b0d93269-b67a-52d5-bef1-ee6aa37667fe

STIX ID: report--b0d93269-b67a-52d5-bef1-ee6aa37667fe

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Five coordinated malicious Chrome extensions (four under databycloud1104 and one as softwareaccess) target Workday, NetSuite, and SuccessFactors to continuously extract session tokens, perform bidirectional cookie injection for immediate account takeover that can bypass MFA, and use DOM manipulation/MutationObserver-based page blocking to prevent administrators from performing remediation; Socket.dev reports these extensions have reached over 2,300 users and employ a multi-extension strategy to maintain persistent, high-impact access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.