Researchers at Socket have identified a supply chain attack where malicious actors acquired legitimate browser extensions for Chrome and Edge and turned them into malware. The campaign involved 19 extensions that were originally safe but later updated with harmful code after being purchased from their developers. This allowed attackers to push malicious updates to users who had installed the extensions when they were still trustworthy. The attackers exploited the trust users place in popular browser tools by purchasing extensions that had existing user bases and positive reviews. Once acquired, they pushed updates containing malware designed to steal data, inject ads, or hijack browsing sessions. Five of the extensions were found to have particularly aggressive behaviors, including keystroke logging and unauthorized access to sensitive websites.
Socket reported that the malicious activity began after the extensions changed hands, with no prior signs of compromise in their original versions. How the Attack Bypassed User Defenses The malicious updates were distributed through official browser stores, meaning they appeared legitimate to users and security systems. Because the extensions were already installed and trusted, many users did not scrutinize the update permissions or notice subtle changes in behavior. Socket noted that the attackers carefully timed the malicious updates to avoid immediate detection, often waiting weeks after acquisition before deploying harmful code. This delay helped the campaign evade automated scanners that look for rapid behavioral shifts. What Makes This Supply Chain Tactic Effective This method leverages the inherent trust in the software update process, where users expect improvements rather than threats.
By compromising the supply chain at the publisher level, attackers bypass traditional defenses that focus on detecting malware in unknown software. The technique is especially dangerous because it targets widely used tools like ad blockers, productivity aids, and themes—extensions users rarely think to remove or monitor closely. Socket emphasized that even security-conscious users can fall victim when the threat comes from a familiar, long-used extension. Frequently Asked Questions How did attackers acquire the extensions? They purchased them from the original developers, who may have sold them due to lack of interest or financial incentive. Why were users unable to detect the malicious updates? The updates came through official channels and appeared as routine improvements, reducing suspicion. What types of data were at risk? Stolen data could include login credentials, browsing history, and form inputs, depending on the extension’s permissions.