#chrome extension Navikit Tiktok Shop Selle seems malicious. Its #cybersecurity badness score is 88/100!
```json
{"id": "bcnicogbehmgcpjhfinaiehfmpipnlad", "score": 88, "platform": "chrome", "name": "Navikit Tiktok Shop Selle"}
```
102 results for “malicious_browser_bot”
#chrome extension Navikit Tiktok Shop Selle seems malicious. Its #cybersecurity badness score is 88/100!
```json
{"id": "bcnicogbehmgcpjhfinaiehfmpipnlad", "score": 88, "platform": "chrome", "name": "Navikit Tiktok Shop Selle"}
```
#chrome extension Meme Coin Tracker seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "pehfheklmebgnepcebgnajlpejbmdogp", "score": 93, "platform": "chrome", "name": "Meme Coin Tracker"}
```
#chrome extension Browsec VPN — Приватный VPN для работы и браузинга в России seems malicious. Its #cybersecurity badness score is 96/100!
```json
{"id": "cloiconpmchdcmbnokhedmfoopddpkkl", "score": 96, "platform": "chrome", "name": "Browsec VPN \u2014 \u041f\u0440\u0438\u0432\u0430\u0442\u043d\u044b\u0439 VPN \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0438 \u0431\u0440\u0430\u0443\u0437\u0438\u043d\u0433\u0430 \u0432 \u0420\u043e\u0441\u0441\u0438\u0438"}
```
#chrome extension Morpho Enhancements seems malicious. Its #cybersecurity badness score is 94/100!
```json
{"id": "fdaakkagehjogjhojpjeelklgagcknkg", "score": 94, "platform": "chrome", "name": "Morpho Enhancements"}
```
#chrome extension Sf Helper seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "ajjkfoidajnfodfdpnndohcpodcmnhle", "score": 98, "platform": "chrome", "name": "Sf Helper"}
```
#chrome extension Metamap seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "jfpelgifknjgdkoibcmaapnhjcnakbih", "score": 93, "platform": "chrome", "name": "Metamap"}
```
#chrome extension Lido App seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "hkbmodekajagpppbpmplamefjfjekehk", "score": 93, "platform": "chrome", "name": "Lido App"}
```
#chrome extension Okx Wallet Tracker Crypto seems malicious. Its #cybersecurity badness score is 100/100!
```json
{"id": "ajdljbgfgdenkjkcpphlgipkbghbmcfj", "score": 100, "platform": "chrome", "name": "Okx Wallet Tracker Crypto"}
```
#chrome extension Mcmaster Smart Lite seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "nmlkcbnplhaffhooaioodjlghepdlopk", "score": 93, "platform": "chrome", "name": "Mcmaster Smart Lite"}
```
#chrome extension Github Exporter seems malicious. Its #cybersecurity badness score is 90/100!
```json
{"id": "cheapakebegonhikckggcbilehdjkgkf", "score": 90, "platform": "chrome", "name": "Github Exporter"}
```
#chrome extension Github File Collapser seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "edoefkpbifgpalopdbikblemhdjhbkja", "score": 93, "platform": "chrome", "name": "Github File Collapser"}
```
#chrome extension Tone — Light By Time seems malicious. Its #cybersecurity badness score is 86/100!
```json
{"id": "bjmjhchaboblphooedaadglpcpjbmeah", "score": 86, "platform": "chrome", "name": "Tone \u2014 Light By Time"}
```
#chrome extension Github Active Forks seems malicious. Its #cybersecurity badness score is 91/100!
```json
{"id": "oflkkabfokadmncdbhdggeedngllccak", "score": 91, "platform": "chrome", "name": "Github Active Forks"}
```
#chrome extension Zoom Workplace Extension seems malicious. Its #cybersecurity badness score is 91/100!
```json
{"id": "fgbkadjnnoadejkncdepkgjocfopjifg", "score": 91, "platform": "chrome", "name": "Zoom Workplace Extension"}
```
#chrome extension Selectorshub seems malicious. Its #cybersecurity badness score is 95/100!
```json
{"id": "ndgimibanhlabgdgjcpbbndiehljcpfh", "score": 95, "platform": "chrome", "name": "Selectorshub"}
```
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
A coordinated campaign of 16 malicious Firefox extensions has been identified targeting cryptocurrency wallet users. The extensions masquerade as wallet portals, desktop utilities, and browser tools while intercepting recovery phrases and private keys during wallet import flows. Four large extensions clone Rabby Wallet (misspelled as Raabby WaIIet), while twelve smaller extensions impersonate OKX Wallet. All variants capture 12- or 24-word mnemonics and private keys, transmitting stolen credentials to attacker-controlled Cloudflare Workers endpoints. Fifteen extensions communicate with icy-star-f45c.workers.dev infrastructure. The campaign reuses code markers, network infrastructure, and credential-handling logic, indicating connection to crypto-theft operations identified in August 2026. Mozilla has unpublished these extensions. Users who entered credentials should immediately create new wallets and transfer assets.
Pulse ID: 6ac74668a88744f8ef47c332
Pulse Link: https://otx.alienvault.com/pulse/6ac74668a88744f8ef47c332
Pulse Author: AlienVault
Created: 2026-10-08 07:29:44
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.
Pulse ID: 6ac49b893a8000cf4c9c1735
Pulse Link: https://otx.alienvault.com/pulse/6ac49b893a8000cf4c9c1735
Pulse Author: CyberHunter_NL
Created: 2026-10-06 06:56:09
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
⚠️ CRITICAL: Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
Eight malicious npm packages (40,767+ downloads) deliver Overlord RAT and movinlike stealer targeting Windows developers. The MALFEX campaign steals browser data, crypto wallets, and messaging credentials. If your development environment installed these packages, assume compromise.
🤖 AI generated summary
Microsoft Warns of ClickFix Browser Cache Smuggling Attacks Bypassing Windows Defenses
Microsoft warns of a sneaky new attack called ClickFix browser cache smuggling, where hackers disguise malicious scripts as harmless image files in your browser cache, allowing them to bypass Windows defenses. This clever trick lets attackers execute their payload without downloading or executing remote…
#BrowserCacheSmuggling #Clickfix #Windows #EmergingThreats #ThreatIntelligence
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ ClickFix Attacks Evolve to Better Hide Malicious Payloads
🔗 https://www.darkreading.com/cyberattacks-data-breaches/clickfix-attacks-evolve-better-hide-malicious-payloads
Threat actors are now hiding payloads by using DNS TXT records and browser cache pre-fetching, making it tougher to spot early attack stages.
Malicious Crypto Shell Packages Target RubyGems https://packetstorm.news/news/view/44956 #news
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers
Researchers have demonstrated an attack chain in which a malicious HEIC image uploaded to a WordPress Media Library can lead to remote code execution in the PHP-FPM process. The risk comes from libheif, a widely used component for reading HEIC, HEIF, and AVIF formats. https://cybersecuritynews.com/malicious-heic-images/
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials https://packetstorm.news/news/view/45055 #news
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
Sixteen malicious Firefox extensions impersonating Rabby and OKX crypto wallets were caught stealing users' recovery phrases, The Hacker News reports. The extensions looked legitimate enough to trick wallet users into handing over the keys to their funds. https://thehackernews.com/2026/10/16-malicious-firefox-extensions-pose-as.html
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html
Eight malicious npm packages downloaded 40,767 times deliver Overlord RAT and stealer
Eight malicious npm packages were downloaded 40,767 times before being taken down, The Hacker News reports. The packages delivered the Overlord remote access trojan and an information stealer to compromised developer machines. https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html
Hacker News: 16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases https://thehackernews.com/2026/10/16-malicious-firefox-extensions-pose-as.html #news #IT
LevelBlue reported malicious attempts against customer systems running Citrix NetScaler ADC and NetScaler Gateway.
Attackers tried to establish hidden access, create administrator accounts and copy configuration files; the findings do not confirm that every attempt succeeded or that data was lost.
Citrix released fixes on September 27.
Its advisory lists 14.1-73.37 and 13.1-64.23, plus corresponding special builds, as m…
https://en.hacks.gr/agnostoi-ekmetalleyontai-keno-asfaleias-se-citrix-netscaler-choris-syndesi/
Socket found 16 malicious Firefox extensions impersonating Rabby and OKX wallets. They intercept wallet-import flows to steal recovery phrases and private keys to Cloudflare Workers, enabling full wallet takeover. #FirefoxSecurity #CryptoTheft #ExtensionSecurity
https://cyberworldops.eu/en/fake-firefox-wallet-extensions-target-rabby-and-okx-recovery-secrets
Researchers identified 16 malicious Firefox add-ons impersonating Rabby and OKX wallet tools.
Four posed as Rabby Wallet and 12 as OKX Wallet.
According to the researchers, the add-ons recorded recovery phrases and private keys when users entered wallet details, then tried to send them to attackers.
All 16 had been removed by October 5, 2026; the article does not report confirmed wallet access or stolen funds.
Any…