logo

Chrome Extensions: Are you getting more than you bargained for?

ID: fffd7674-e08a-5cbe-994b-ddf30f70ada9

STIX ID: report--fffd7674-e08a-5cbe-994b-ddf30f70ada9

Feed Name: security.com

Threat Score
70/100

Date Published: 2026-01-26

Date Updated: 2026-04-29

Author: Yuanjing Guo, Tommy Dong

...
...

### Executive Summary Symantec researchers identified four Chrome Web Store extensions (Good Tab, Children Protection, DPS Websafe, Stock Informer) that exhibit malicious or vulnerable behaviors—undisclosed clipboard access to remote HTTP domains, cookie harvesting and DGA-backed C2 with remote code execution, search hijacking and user tracking, and an exploitable XSS—affecting a combined user base in excess of 100,000; the report includes technical snippets, IOCs (extension IDs and domains), and remediation advice to uninstall the extensions and block related infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.