home.social

#chromeextension — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #chromeextension, aggregated by home.social.

  1. PEEP: A Browser RAT Posing as a Chrome Extension

    PEEP is a Chromium-based post-exploitation toolkit disguised as 'Smart Bookmarks' that transforms Chrome and Edge browsers into persistent backdoors. Requiring prior administrative access, it bypasses Web Store security by forging Chromium integrity values and uses native-messaging to extend beyond browser telemetry to full host-level command execution. The malware beacons every 30 seconds over unencrypted HTTP, exfiltrating browsing history, cookies, credentials, and session data. Built on the open-source RedExt framework with significant enhancements, PEEP combines browser surveillance with filesystem manipulation, shell command execution, and process discovery. The infrastructure exposed development artifacts including source code, signing keys, and Traditional Chinese testing logs, indicating a Chinese-speaking operator using AI-assisted development. The toolkit demonstrates sophisticated persistence through HMAC forgery, enterprise policies, and ScriptCache manipulation.

    Pulse ID: 6a9eb13dfccfac432c46d96e
    Pulse Link: otx.alienvault.com/pulse/6a9eb
    Pulse Author: AlienVault
    Created: 2026-09-07 12:42:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chinese #Chrome #ChromeExtension #Cookies #CyberSecurity #Edge #GRIT #HTTP #InfoSec #Mac #Malware #OTX #OpenThreatExchange #RAT #RCE #bot #AlienVault

  2. Malicious Chrome Extension Can Steal Login Sessions and Turn PCs Into Remote Backdoors

    Indicators extracted from public reporting. Source: socradar.io/blog/peep-browser-

    Pulse ID: 6a9e7c2ce1129dcc5ae37c04
    Pulse Link: otx.alienvault.com/pulse/6a9e7
    Pulse Author: CyberHunter_NL
    Created: 2026-09-07 08:56:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chrome #ChromeExtension #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL