CHROMEPUSH is a C++ data-stealing malware family deployed in UNC1069 intrusions, assessed in the provided content as DPRK-linked and financially motivated, particularly against cryptocurrency and FinTech targets. It is described as a malicious browser extension stealer targeting Chromium-based browsers, specifically Google Chrome and Brave. CHROMEPUSH masquerades as a Google Docs Offline editing tool and installs as a Chromium native messaging host for persistence. Reported installation artifacts include copying itself to %HOME%/Library/Application Support/Google/Chrome/NativeMessagingHosts/Google Chrome Docs and creating a manifest file named com.google.docs.offline.json in the same NativeMessagingHosts directory. The malware collects keystrokes, username and password inputs, browser cookies, and browser login data, uploads stolen data to a web server, and in some reporting may optionally capture screenshots and exfiltrate data via HTTP POST. In the observed macOS intrusion chain, SUGARLOADER, a C++ downloader, was used solely to deploy CHROMEPUSH. The malware was part of a broader toolset that also included WAVESHAPER, HYPERCALL, DEEPBREATH, and SILENCELIFT, used for deep and persistent compromise of individual machines.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Their tooling, including the WAVESHAPER backdoor, HYPERCALL downloader, DEEPBREATH data miner, and CHROMEPUSH browser extension stealer, was designed for deep, persistent compromise of individual machines.
...several new malware families, such as... CHROMEPUSH... CHROMEPUSH also acts as a data stealer... deployed as a browser extension to Google Chrome and Brave browsers by masquerading as a tool for editing Google Docs offline.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
With that access, publishing a malicious package to npm requires no additional authentication bypass.
CHROMEPUSH... installs itself as a browser extension targeting Chromium-based browsers, such as Google Chrome and Brave, to collect keystrokes, username and password inputs, and browser cookies | CHROMEPUSH establishes persistence by installing itself as a native messaging host for Chromium-based browsers. For Google Chrome, CHROMEPUSH copies itself to %HOME%/Library/Application Support/Google/Chrome/NativeMessagingHosts/Google Chrome Docs and creates a corresponding manifest file, com.google.docs.offline.json, in the same directory.
CHROMEPUSH... installs itself as a browser extension targeting Chromium-based browsers, such as Google Chrome and Brave, to collect keystrokes, username and password inputs, and browser cookies
Browser Data: Copies cookies, login data, and local extension settings from major browsers including Google Chrome, Brave, and Microsoft Edge across all user profiles
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A browser extension stealer used to support deep, persistent compromise of individual machines.
C++ Chromium-focused stealer/keylogger that installs as a native messaging host disguised as a Google Docs offline extension; logs keystrokes, captures credentials, extracts cookies, and may capture screenshots; exfiltrates via HTTP POST.
Custom data-mining/stealer tooling (implied browser-focused, potentially via extension) used in a North Korea-linked crypto-targeting intrusion to harvest browser and related user data for theft and impersonation.
C++ data-stealing capability delivered as a malicious Chrome/Brave browser extension; can keylog, capture credential inputs, and steal cookies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.