#malicious-extensions

[ follow ]
#supply-chain-attack
fromThe Hacker News
18 hours ago
Information security

GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools

GlassWorm infected Visual Studio Marketplace and Open VSX with 24 malicious extensions that steal credentials, drain cryptocurrency, and propagate via compromised packages.
fromTechzine Global
1 day ago
Information security

Glassworm malware reappears within VS Code ecosystem

Glassworm malicious extensions persistently infiltrate developer marketplaces, conceal payloads, and use resilient, distributed command-and-control mechanisms that are difficult to detect or block.
Information security
fromComputerworld
1 month ago

AI browsers can be abused by malicious AI sidebar extensions: Report

Malicious browser extensions can spoof AI sidebars to steal data, redirect users, or install backdoors; organizations must audit extensions and enforce zero-trust controls.
Information security
fromDevOps.com
2 months ago

WhiteCobra Targets Developers with Dozens of Malicious Extensions - DevOps.com

WhiteCobra distributes malicious VSCode and Open VSX extensions to steal cryptocurrency wallets from developers using VSCode, Cursor, and Windsurf.
fromTheregister
4 months ago

Browser hijacking campaign infects 2.3M Chrome, Edge users

The Geco color picker extension, while appearing safe and helpful, hijacks browser sessions, tracks user activities, and backdoors victims' web browsers, highlighting significant security concerns.
Privacy professionals
[ Load more ]