Researchers identified a browser-extension campaign involving 19 malicious Chrome and Microsoft Edge extensions, including 14 published as apparently legitimate tools and five acquired from their original developers before receiving malicious updates. The extensions, reportedly installed by as many as 2.3 million users, contact attacker-controlled command-and-control infrastructure, retrieve replaceable modules, bypass Content Security Policy protections, and inject code into pages opened by targeted victims.
The extensions can exfiltrate browsing histories, credentials, payment data, Facebook and LinkedIn information, cryptocurrency assets, and hardware-wallet seed phrases. They also report visited URLs to attacker APIs and can redirect tabs to server-selected destinations for phishing and session theft; observed infrastructure includes ebmitab[.]com, abmitab[.]com, and addmitab[.]com. Some extensions replace pages with fake browser-update prompts that use ClickFix social engineering to induce victims to run malicious commands, extending compromise beyond the browser. Organizations should allowlist extensions, remove affected add-ons, and reset potentially exposed credentials and sessions.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
The identified extensions contacted command-and-control servers for changeable modules that disabled Content Security Policy and injected code into victims' browsed pages. Modules stole web-form credentials and payment data, targeted social-media and cryptocurrency accounts and wallet seed phrases, and displayed ClickFix prompts intended to convince victims to execute malicious commands outside the browser.
Researchers reported finding 18 malicious Google Chrome extensions and one malicious Microsoft Edge extension, which they assessed were probably part of one campaign based on shared code and methods. The extensions were either initially presented as legitimate or acquired from legitimate developers before malicious functionality was added through updates.
Koi Security reported that browser extensions trusted by Google and Microsoft had been installed by approximately 2.3 million users and were malware.
Researchers documented malicious or compromised browser extensions that sent visited URLs to attacker-controlled API endpoints and redirected tabs to server-supplied destinations, enabling potential phishing and credential or session theft. Examples included Flash Player for Chrome and SearchGPT, which communicated with ebmitab[.]com, abmitab[.]com, or addmitab[.]com.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
kaspersky.ru
Open sourceshroudcloud.io
Open sourceblog.koi.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.