logo

It's time to treat browser extensions like supply chain attack vectors

ID: 34fe908d-b043-522d-bee2-67e8e31ab4b7

STIX ID: report--34fe908d-b043-522d-bee2-67e8e31ab4b7

Feed Name: Aikido Security's Blog

Threat Score
80/100

Date Published: 2026-04-24

Date Updated: 2026-07-24

...
...

The report explains how a Context.ai browser extension and an infostealer installed on an employee device led to a supply-chain compromise that exposed an OAuth token and enabled a large-scale attack on Vercel; it warns that browser extensions (which auto-update silently and can hold broad privileges) are an underappreciated supply-chain risk and recommends applying dependency-style scanning, continuous auditing of installed extensions, and pre-install blocking tied to threat intelligence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.