Tech

Malicious “polymorphic” Chrome extensions can mimic other tools to trick victims

Share
Share


  • Researchers find malicious browser extensions can assume the appearance of any other installed in the browser
  • It can also disable other extensions, completely tricking the victim
  • The extension can steal sensitive passwords, cryptos, and more

Cybersecurity researchers have found malicious shapeshifting Google Chrome browser extensions in the wild, able to change their appearance to pretty much anything else installed on the target device, opening the doors for credential theft, cryptocurrency theft, and possibly even wire fraud.

Researchers from SquareX said they spotted a malicious browser extension which at first, seems benign. It can be an “unassuming AI tool”, or pretty much anything else. When it’s first installed, it will behave as expected, for at least a while, while it analyzes which other extensions are installed in the browser.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Microsoft is making all new accounts passwordless by default
Tech

Microsoft is making all new accounts passwordless by default

New Microsoft accounts will use passkeys by default, company reveals Existing users...