logo

Malicious Chrome extensions can spoof password managers in new attack

ID: d13a5ee6-c766-5abb-8ac1-66aa15422722

STIX ID: report--d13a5ee6-c766-5abb-8ac1-66aa15422722

Feed Name: Bleeping Computer

Date Published: 2025-03-06

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

SquareX Labs details a practical polymorphic Chrome extension attack that identifies installed extensions, disables or hides a targeted one, and then impersonates it (e.g., 1Password) to present realistic phishing prompts that capture user credentials before reverting to its original state. The method relies on the chrome.management API and UI deception, with no current Chrome defenses to block abrupt icon/HTML changes. Researchers recommend Google add safeguards or user notifications to mitigate this impersonation risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.