Credential-stealing Chrome extensions target enterprise HR platforms
ID: b78bdc98-4805-5422-a7dd-ca0144e2e49b
STIX ID: report--b78bdc98-4805-5422-a7dd-ca0144e2e49b
Feed Name: Bleeping Computer
Threat Score
Researchers discovered five malicious Chrome extensions on the Chrome Web Store posing as productivity/security tools for Workday, NetSuite, and SuccessFactors that stole authentication cookies (notably "__session"), blocked security/administration pages to hinder incident response, and supported bidirectional cookie injection for immediate session takeover; the extensions shared infrastructure and code patterns, had ~2,300 installs, and were reported to Google and removed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
