Our final blog post this week explores the origins of malicious browser extensions, why they remain a persistent threat, and the unique characteristics that make them particularly challenging to detect and defend against.
For most users, browser extensions have been a means of increasing productivity, blocking ads, and serving as our grammar police. Due to the perceived secure nature of modern browsers, coupled with the token of validity from web stores, browser extensions have become a prolific mechanism for threat actors to take advantage of.
Whilst malicious browser extensions have plagued the internet for many years now, there was a notable shift in how threat actors were abusing these extensions starting late 2024. The threats went from simple adware annoyances to sophisticated identity theft, session hijacking, fingerprinting, and data exfiltration capabilities.
The first question most people ask when faced with a malicious browser extension is how did this extension find its way onto the browser extension store? For an extension to become available for install, it needs to be validated by the respective browser. An example of Chrome’s validation and review process can be viewed here. Additionally, some browsers have badges that can be awarded to extensions based on performance and verification. Chrome’s extension badge system can be viewed here.
If our browsers are reviewing and validating extensions before and after being made available to install via their store, how are malicious extensions such a prolific threat? There are a few methods threat actors have been using to action their objectives here:
The most popular method threat actors use for deploying malicious extensions is not actually attempting to push their own extension past the browser review and validation process. The easiest way to host a valid looking extension is to steal one. If you read our Wednesday blog, you will be familiar with the various Phishing techniques used to compromise identity. These same techniques have been used against developers of legitimate web extensions to allow threat actors to gain control of the extensions source code. With this level of access to the extension, they are able to simply trojanize the extension by adding malicious code where they see fit.
Many trusted web extensions have a large user base but are no longer being maintained by their original developers. This creates an opportunity for threat actors to offer purchasing the validated extension. Once purchased, complete ownership of the extension and its source code is handed to the malicious operators to pollute at will.
The browser review and validation process relies upon a standardised formatting of how the extension has been developed. As stated in publicly available documentation, the process is both automated and human reviewed. Malware developers throughout history, have always found techniques that completely bypass things like Antivirus signatures or more recently, behavioural analysis engines. The same techniques have been observed with threat actors sneaking malicious code into their browser extensions, passing review and validations, and landing their extension on the browser store. An example of how this can work is placing invasive permissions in optional permission sets, only requesting when the user attempts to actively use the extension, not at time of install.
There have been campaigns such as the 2024 ShadyPanda campaign where threat actors have patiently built web extension reputation for years before deploying their malicious payloads. This is especially difficult to defend against, as the operators have had full control over the web extension since their initial development, with little signs of malicious intent.
Whilst less prominent, there are services being offered by threat actors on underground forums that promise to evade extension review and validation processes. The seller has already established a verified browser extension, leaving the buyer process very simple: purchase the service and you will be given access to a dashboard from which to deploy malicious payloads via the extension.
We will be breaking down an example of a malicious browser extension currently available for install on the Chrome Web Store. Not only has this extension made itself available on the store, it has managed to obtain a “Featured” badge, further providing a false sense of security for end users. The extension is essentially spyware trojanised as a legitimate voice recording extension.
The extension was analysed and reported on 08/10/2026.
The browser extension is Simple Audio Voice Sound Recorder and boasts the following features:
Simple voice recording dictation, and mic testing directly from Chrome.
A question that should be answered immediately: If this extension is malicious, why is it available on the Chrome Web Store?
As mentioned in Evasion through code, the developers for this application have been very intentional about how they request for permissions. If we look at the extension manifest.json, we can see the extension does not immediately ask for invasive permissions like all_urls and scripting upon installing the extension:
Instead, the developers use social engineering techniques to prompt the user to provide these permissions only after installation. This is a purpose-built permission flow designed to avoid scrutiny at time of install.
When the end user first clicks on the browser extension icon within Chrome, the social engineering begins. A “Consent” box popup will ask the end user to agree to use the extensions “Safe Audio Streaming” feature.
This popup is crafted by the developers to lure the end user into a false sense of security, which impacts how they react to the subsequent pop up box consenting to the additional permissions required for the malicious code to work:
The extension is now fully configured to do 2 things:
Pose as a legitimate extension by providing a legitimate voice recording solution.
The malicious code is all stored in a safe-browsing.js, a file named to support the “Safe Audio Streaming” claim as a legitimate security feature. The script is imported by the extension’s background service worker which enables it to run when the extension starts, including at browser launch. Every sensitive string in the file is hidden behind a custom character-shift cipher, which prevents static analysis through keyword search. The threat actor’s Command and Control (C2) domain does not need to be present in the extension at all. Instead, the safe-browsing.js script retrieves it at runtime from the DNS TXT record of a bootstrap domain, using DNS-over-HTTPS (DoH) queries to Google, Cloudflare and Alibaba. This bypasses monitoring and allows the threat actor to pivot infrastructure without needing to update the extension.
An important section of the safe-browsing.js script below has been decoded for readability:
At the time of writing, the DNS TXT record for bkp.v1.fsdifhj[.]com was simply “fsdifhj[.]com”. So whilst the mechanism is there to completely exclude the domain from being present in code, the operators have not utilised it.
The gathered data is sent to the C2 infrastructure at each page visit. The data is LZ-String compressed and sent to cs.fsdifhj[.]com/api/v2/hazard/verify. Hooking JSON.stringify before compression, we are able to use DevTools within the extension's service worker to log each record, giving us a clean output of what is sent to the operator:
The extension behaviour described above can be likened to other forms of malware, where the operator has purposefully crafted techniques that hide how and where sensitive information is sent from the impacted device.
The indicators found in this extension have also been observed sharing the same infrastructure as previously reported malicious browser extension campaigns.
Currently, out of the box detection capabilities for malicious browser extensions is lacking. Due to sheer numbers of malicious extensions, the lack of targeted tracking, and the nuances of host-based telemetry – many malicious extensions go undetected for weeks and sometimes months.
Koi Security has been a long-time leader in the malicious extension space and were acquired by Palo Alto Networks in April 2026. Their Koi Agentic Endpoint Security offering now covers AI applications, open-source packages, browser extensions, and Model Context Protocols.
Additionally, Palo Alto offers Prisma Browser, built with Enterprise Security at the forefront of design.
Microsoft are developing capabilities with Defender Vulnerability Management. CrowdStrike have a similar offering with Falcon Exposure Management.
There are options to curate or follow malicious browser extension watchlists from which to alert upon, however this option comes with a significant amount of operational overhead.
Most modern browsers have a native sync feature which allows browser extensions to follow their account across devices. With regards to malware, this is a distinct behaviour that needs to be taken into consideration when performing malicious browser extension remediation. Unlike most forms of malware, browser extensions can persist off disk.
Take the following scenario:
$user is a nurse at $organisation.
If browser extension allow-listing is not configured in the environment, there are 2 remediation options:
Depending on the malicious browser extension capabilities, there will be additional remediation actions that need to be completed. As a matter of pre-caution, it is recommended to perform password resets and session revocations for all impacted users. Whilst it is possible to analyse the browser extension for behaviours, the low impact of these actions are justifiable.
The proliferation of malicious browser extensions and their sophistication make way for a clear recommendation with regards to prevention mechanisms, and that is allow-listing.
Most vendors now have methods for allow-listing browser extensions. It is highly recommended to take advantage of these controls. An example of allow-listing implementation would be via Chrome and Edge extension policies deployed via either Microsoft’s Intune or Group Policy.
If allow-listing is not an option, then other options should be considered including:
Browser Security Extensions such as the Prisma browser extension.
Blocking malicious browser extension related IOCs via XDR or perimeter appliances.
| Type | Indicator | Notes |
| Domain | fsdifhj[.]com | Bootstrap + C2 domain |
| IP Address | 67.43.229[.]42 | id.fsdifhj[.]com |
| IP Address | 72.10.166[.]154 | cs.fsdifhj[.]com |
| Extension ID | cplfpogibkkmmficaepjiemimenignoh | Chrome Store extension ID |