Malicious GhostPoster browser extensions found with 840,000 installs
ID: 28ba6ead-009e-5c6b-9171-a24b7c1cb114
STIX ID: report--28ba6ead-009e-5c6b-9171-a24b7c1cb114
Feed Name: Bleeping Computer
LayerX and prior researchers uncovered the GhostPoster campaign: 17 malicious browser extensions (Chrome, Firefox, Edge) with ~840,000 combined installs that conceal heavily obfuscated JavaScript payloads inside extension images/icons. At runtime the extensions extract, decode, and execute staged payloads that monitor browsing, hijack affiliate links, inject invisible iframes for ad/click fraud, and provide backdoor capabilities; researchers observed an evolved variant that moves staging into background scripts and uses bundled image files as covert payload containers. The extensions have been removed from stores, but previously installed users remain at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
