Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      GM Bets on Affordable Chevy Bolt to Navigate Uncertain EV Market

      March 14, 2026

      DOJ Signals It Will Not Break Up Live Nation And Ticketmaster Despite Antitrust Fight

      March 14, 2026

      Anthropic Unveils AI Code Review System To Manage Surge Of Machine-Generated Software

      March 14, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        Electric Air Taxis Prepare For Real-World Launch Across 26 U.S. States

        March 14, 2026

        Viral ‘Pro-Dubai’ Influencer Script Raises Questions About Coordinated Messaging

        March 14, 2026

        California Colleges Spend Hundreds of Thousands on AI Chatbots That Get Answers Wrong

        March 14, 2026

        NASA Impact Test Quietly Alters Asteroid’s Path Around The Sun

        March 13, 2026

        Hybrid Muscle: Corvette ZR1X Signals American Performance Renaissance

        March 13, 2026
      • AI

        Anthropic Unveils AI Code Review System To Manage Surge Of Machine-Generated Software

        March 14, 2026

        California Colleges Spend Hundreds of Thousands on AI Chatbots That Get Answers Wrong

        March 14, 2026

        Viral ‘Pro-Dubai’ Influencer Script Raises Questions About Coordinated Messaging

        March 14, 2026

        AI Writing Tool Draws Criticism For Mimicking Real Experts Without Permission

        March 13, 2026

        Cyber Warfare Emerges as Central Battlefield in U.S.–Israel Confrontation With Iran

        March 13, 2026
      • Security

        Cyber Warfare Emerges as Central Battlefield in U.S.–Israel Confrontation With Iran

        March 13, 2026

        Integrated Defense Systems Aim To Shield Critical Infrastructure From Cyber Warfare

        March 13, 2026

        The Creepy Truth About Smartphone Tracking And Why Ads Seem To Read Your Mind

        March 12, 2026

        Israel Emerges As The World’s Most Targeted Nation For Geopolitical Cyberattacks In 2025

        March 12, 2026

        X Moves To Contain AI War Disinformation As Fake Iran Conflict Footage Floods Social Media

        March 11, 2026
      • Health

        Scientists Teach Living Human Brain Cells To Play Doom

        March 11, 2026

        Health Data Of 3.4 Million Americans Exposed In Major Healthcare Technology Breach

        March 10, 2026

        Expert Testimony Warns Social Media Is Rewiring Children’s Brains

        March 8, 2026

        Courtroom Scrutiny Grows Over Claims Instagram Tracked Usage While Pursuing Teens

        March 5, 2026

        Smartphone Use Creates A Daily “Vicious Cycle” Of Disconnection And Disengagement

        March 4, 2026
      • Science

        Electric Air Taxis Prepare For Real-World Launch Across 26 U.S. States

        March 14, 2026

        NASA Impact Test Quietly Alters Asteroid’s Path Around The Sun

        March 13, 2026

        Hybrid Muscle: Corvette ZR1X Signals American Performance Renaissance

        March 13, 2026

        Israel’s Iron Beam Laser Defense Moves From Concept Toward Battlefield Reality

        March 13, 2026

        How Engineers Modernized Chornobyl’s Nuclear Control Systems In The 1990s

        March 12, 2026
      • Tech

        Apple Quietly Expands Executive Bench With Three New Leaders

        March 8, 2026

        Silicon Valley’s Political Experiment Faces Internal Revolt

        March 7, 2026

        Sam Altman Says ‘AI Washing’ Is Being Used to Mask Corporate Layoffs

        February 28, 2026

        Zuckerberg Testifies In Landmark Trial Over Alleged Teen Social Media Harms

        February 23, 2026

        Gay Tech Networks Under Spotlight In Silicon Valley Culture Debate

        February 23, 2026
      TallwireTallwire
      Home»Cybersecurity»New Malicious Chrome Extensions Steal Enterprise HR Credentials and Enable Full Account Takeovers
      Cybersecurity

      New Malicious Chrome Extensions Steal Enterprise HR Credentials and Enable Full Account Takeovers

      Updated:February 21, 20264 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      Google Rolls Out Emergency Patch for Major Chrome Zero-Day Exploit
      Google Rolls Out Emergency Patch for Major Chrome Zero-Day Exploit
      Share
      Facebook Twitter LinkedIn Pinterest Email

      Security researchers have uncovered a coordinated campaign of malicious Google Chrome browser extensions that were publicly available in the Chrome Web Store and disguised as legitimate productivity or security tools. These extensions specifically targeted widely used enterprise human resources (HR) and enterprise resource planning (ERP) platforms such as Workday, NetSuite, and SAP SuccessFactors, tricking users into installing them and then quietly stealing authentication credentials and session tokens. Once installed, the extensions performed a range of harmful actions including siphoning cookies tied to login sessions to remote attackers, blocking access to administrative security pages so legitimate incident response is obstructed, and even injecting stolen authentication tokens back into browsers to facilitate account hijack without needing usernames, passwords, or multi-factor codes. The campaign affected over 2,300 installations before removal, and though the malicious add-ons were taken down from the official Chrome Web Store, risks remain if users installed them through third-party sources. Security experts warn that this incident underscores persistent weaknesses in browser extension vetting and enterprise endpoint security practices.

      Sources:

      https://www.bleepingcomputer.com/news/security/credential-stealing-chrome-extensions-target-enterprise-hr-platforms/
      https://www.scworld.com/news/workday-netsuite-and-successfactors-sessions-targeted-by-malicious-chrome-extensions
      https://www.thehackernews.com/2026/01/five-malicious-chrome-extensions.html

      Key Takeaways

      • A suite of five malicious Chrome extensions masqueraded as helpful enterprise tools to steal HR/ERP platform credentials and session cookies.
      • These extensions could block security admin pages and facilitate full session hijacking, bypassing even multi-factor authentication.
      • The operation highlights ongoing enforcement and extension-vetting gaps in browser extension ecosystems that threat actors exploit.

      In-Depth

      In the latest sign that threat actors are finding new ways to exploit trusted software layers, cybersecurity researchers have disclosed a coordinated campaign of malicious Chrome extensions that targeted enterprise human resources (HR) and enterprise resource planning (ERP) systems. These extensions, which were publicly available through Google’s Chrome Web Store, posed as productivity enhancers and security tools to users of enterprise applications such as Workday, NetSuite, and SAP SuccessFactors. Once installed, they quietly conducted credential theft and session hijacking operations that could give attackers unfettered access to corporate systems.

      Researchers first identified the malicious extensions through analysis conducted by Socket’s Threat Research Team and others, noting that although the extensions appeared to offer value-added services for HR and ERP users, they in fact contained code engineered to steal authentication cookies, interfere with security processes, and hand over control of authenticated sessions to remote attackers. These session cookies — the tokens that allow authenticated access — were exfiltrated to attacker-controlled infrastructure on a frequent, automated cadence, permitting attackers to maintain control even if a user logged out or attempted to reauthenticate. Moreover, some of the extensions were found to block access to key administrative pages within affected platforms, effectively shut-ting out legitimate security teams from their own systems during an incident.

      The extensions disguised themselves under various names and developer identities, making them difficult to detect with superficial scrutiny. Collectively they garnered more than 2,300 installs before Google removed them from the Web Store, but the threat persists: malicious extension code often remains in circulation on third-party download sites or through offline distribution. Enterprises that rely on SaaS platforms such as Workday or NetSuite for mission-critical HR and financial functions face a heightened risk when their employees install browser extensions that have broad permissions.

      This incident is a stark reminder that browser extensions, despite their utility, are an inherently risky attack surface. Many enterprises treat browser extensions as benign components of everyday workflows, but these plugins run with the same privileges as the browser itself and can access sensitive data across domains when granted the necessary permissions. This attack chain — starting with social engineering and ending in enterprise account takeover — illustrates the ease with which browser trust can be abused and why strict governance, user education, and technical controls are necessary.

      Enterprise security teams should be conducting rigorous inventories of permitted extensions, enforcing policies that restrict installation to vetted add-ons, and applying endpoint protection measures that can detect anomalous extension activities. For users, the lesson is equally sobering: just because an extension is available from an official store does not guarantee that it is safe — threat actors have repeatedly found ways to bypass vetting mechanisms. Companies should consider deploying hardened browser environments with extension whitelisting and integrate multi-factor authentication and continuous session monitoring as essential parts of their cybersecurity posture.

      The broader implications are clear: as cloud adoption grows and more corporate access happens through web browsers, attackers will continue to evolve their tactics to exploit the browser as a trusted platform. Organizations must adapt by strengthening extension governance and reinforcing endpoint security practices to mitigate these evolving threats.

      Tim Cook
      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleAdobe Rolls Out New AI-Powered Video Editing Tools in Premiere and After Effects
      Next Article Robot Lip-Sync Breakthrough: Machine Learns Realistic Speech Movement from YouTube

      Related Posts

      DOJ Signals It Will Not Break Up Live Nation And Ticketmaster Despite Antitrust Fight

      March 14, 2026

      GM Bets on Affordable Chevy Bolt to Navigate Uncertain EV Market

      March 14, 2026

      Electric Air Taxis Prepare For Real-World Launch Across 26 U.S. States

      March 14, 2026

      Anthropic Unveils AI Code Review System To Manage Surge Of Machine-Generated Software

      March 14, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      Electric Air Taxis Prepare For Real-World Launch Across 26 U.S. States

      March 14, 2026

      Viral ‘Pro-Dubai’ Influencer Script Raises Questions About Coordinated Messaging

      March 14, 2026

      California Colleges Spend Hundreds of Thousands on AI Chatbots That Get Answers Wrong

      March 14, 2026

      NASA Impact Test Quietly Alters Asteroid’s Path Around The Sun

      March 13, 2026
      Popular Topics
      Series B Tesla Satya Nadella Taiwan Tech Tim Cook Tesla Cybertruck Series A UAE Tech Sam Altman trending Sundar Pichai SpaceX picks spotlight Samsung Qualcomm Quantum computing Ransomware Startup Robotics
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.