logo

Fake extension crashes browsers to trick users into infecting themselves

ID: 5426a837-100d-5848-8c0a-8c86d1a849a9

STIX ID: report--5426a837-100d-5848-8c0a-8c86d1a849a9

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-01-20

Date Updated: 2026-04-28

...
...

Researchers uncovered a Chrome Web Store impostor extension that deliberately crashes the browser via a resource-exhausting loop, then shows a fake recovery instruction prompting users to paste and execute a clipboard command; following that social-engineering step the attacker deploys malware, fingerprinting domain membership to install a Python RAT (ModeloRAT) on corporate devices while delivering an unknown/test payload on others. The extension phones home to a misspelled domain (nexsnield.com), waits 60 minutes before triggering to evade quick detection, and was removed from the store but may resurface; recommended mitigations include avoiding executing copied commands, installing only trusted extensions, and using up-to-date anti-malware/browser protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.