logo

Malicious Google Chrome Extensions Hijack Workday and Netsuite

ID: 509d146b-0866-54d8-8fd2-de3ad3af89f3

STIX ID: report--509d146b-0866-54d8-8fd2-de3ad3af89f3

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-01-19

Date Updated: 2026-04-22

...
...

A set of five coordinated malicious Google Chrome extensions (DataByCloud 2, Tool Access 11, DataByCloud Access, Data By Cloud 1, Software Access) were distributed via the Chrome Web Store posing as productivity/security tools and targeted HR and ERP platforms (Workday, Netsuite, SAP SuccessFactors). Once installed they exfiltrated authentication cookies and session tokens to a C2 server every 60 seconds, enabled session hijacking, encrypted C2 traffic, and deliberately blocked remediation (preventing password changes and admin lockouts); roughly 2,300 users downloaded the extensions before removal. Socket recommends using Chrome Enterprise extension allowlists and monitoring for extensions with similar permissions and targeting patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.