Malicious Google Chrome Extensions Hijack Workday and Netsuite
ID: 509d146b-0866-54d8-8fd2-de3ad3af89f3
STIX ID: report--509d146b-0866-54d8-8fd2-de3ad3af89f3
Feed Name: Infosecurity Magazine (News)
A set of five coordinated malicious Google Chrome extensions (DataByCloud 2, Tool Access 11, DataByCloud Access, Data By Cloud 1, Software Access) were distributed via the Chrome Web Store posing as productivity/security tools and targeted HR and ERP platforms (Workday, Netsuite, SAP SuccessFactors). Once installed they exfiltrated authentication cookies and session tokens to a C2 server every 60 seconds, enabled session hijacking, encrypted C2 traffic, and deliberately blocked remediation (preventing password changes and admin lockouts); roughly 2,300 users downloaded the extensions before removal. Socket recommends using Chrome Enterprise extension allowlists and monitoring for extensions with similar permissions and targeting patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
