Chrome extension fake as others to steal data
-
https://www.ghacks.net/2025/03/10/new-polymorphic-chrome-extensions-fake-others-to-steal-your-data/
The researchers highlight several key attacks that may be executed using polymorphic extensions:
Unauthorized transfer of cryptocurrencies using crypto walletsUnauthorized transactions using banking appsUnauthorized access to monitor, write and send confidential documents/ emails with productivity tools (e.g. grammar checkers, automation tools)Unauthorized access to read and modify code base via developer toolsSquareX informed Google about this new type of malicious extension. While there is no direct defense against polymorphic extensions, users may verify Chrome extensions before they install them.