It's time to treat browser extensions like supply chain attack vectors
ID: 34fe908d-b043-522d-bee2-67e8e31ab4b7
STIX ID: report--34fe908d-b043-522d-bee2-67e8e31ab4b7
Feed Name: Aikido Security's Blog
The report explains how a Context.ai browser extension and an infostealer installed on an employee device led to a supply-chain compromise that exposed an OAuth token and enabled a large-scale attack on Vercel; it warns that browser extensions (which auto-update silently and can hold broad privileges) are an underappreciated supply-chain risk and recommends applying dependency-style scanning, continuous auditing of installed extensions, and pre-install blocking tied to threat intelligence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
