Malicious TikTok Downloader Extensions Quietly Compromised 130K Users
ID: ebe722fb-5f06-5763-9cbb-2140c862c1f7
STIX ID: report--ebe722fb-5f06-5763-9cbb-2140c862c1f7
Feed Name: TechRepublic Security
LayerX researchers uncovered a widespread campaign of at least 12 interrelated browser extensions marketed as TikTok video downloaders that built user trust by providing expected functionality but secretly collected high-entropy fingerprinting data, used delayed activation, and leveraged attacker-controlled remote configuration servers to change behavior post-installation; the campaign impacted more than 130,000 users across Chrome and Edge and highlights systemic weaknesses in extension permission models and marketplace review processes, with recommended defenses including allowlists, least-privilege, monitoring, browser isolation, and DLP integration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
