Password Manager Extension Hijack in Browser Store
A malicious extension update briefly reached the official browser store and attempted vault credential interception. Rapid takedown limited spread but not initial installs.
## What happened An attacker gained access to the extension publishing workflow and pushed a trojanized build. ## Why this matters beyond one victim Browser extension ecosystems have high trust and broad user bases, making compromise disproportionately impactful. ## Technical notes Payload logic targeted autofill events and attempted outbound data transfer on specific banking domains. ## What happened An attacker gained access to the extension publishing workflow and pushed a trojanized build. Why this matters: validate exposure and assign an owner if affected. A malicious extension update briefly reached the official browser store and attempted vault credential interception.
CONTENT OPTIMIZATION · AEO/GEO
Not yet scored. Next refresh: 02:00 UTC.
audit trail / provenance0
Provenance
Claims tie surfaced fields back to sources, models, or heuristics.
No structured claims yet — severity uplift rationale still applies below.
What changed
Append-only revisions when ingest or analysts evolve the record.
No revision rows stored yet.
discussion
Sign in to join the thread and vote on comments.
Loading comments…