logo

Moving up the Assemblyline: Exposing malicious code in browser extensions

ID: 79c9b122-6e3e-5bc6-b7de-f00c67455f81

STIX ID: report--79c9b122-6e3e-5bc6-b7de-f00c67455f81

Feed Name: Red Canary

Threat Score
75/100

Date Published: 2026-03-12

Date Updated: 2026-04-29

Author: Tre Wilkins

...
...

This blog explains a proactive workflow using Assemblyline to detect malicious browser extension updates by submitting both old and new extension packages for static analysis, comparing differences (new domains, updated service workers/content scripts, new permissions, new Assemblyline detections, anomalous script characteristics), and raising alerts based on five tuned detection rules; the approach was backtested against five real-world malicious extension updates (including Cyberhaven and Trust Wallet) and successfully identified most compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.