The hidden risks of browser extensions – and how to stay safe
ID: 336e9583-e995-57f4-ad85-fd4a6c4a82e3
STIX ID: report--336e9583-e995-57f4-ad85-fd4a6c4a82e3
Feed Name: WeLiveSecurity (ESET Research)
This advisory highlights the growing risk of malicious browser extensions—often masquerading as ad blockers, PDF tools, or even security add-ons—that can steal credentials and session cookies, redirect users to phishing or malware sites, inject ads, backdoor browsers, and mine cryptocurrency. It outlines common distribution methods (official store abuse, sideloading, hijacked legitimate extensions) and recommends mitigations such as using official stores, scrutinizing developer reputation and permissions, keeping browsers updated, enabling MFA, leveraging safe/secured browsing modes, and deploying reputable security software with periodic scans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
