Five malicious Chrome extensions disguised as productivity tools were discovered stealing session tokens from enterprise HR and ERP platforms like Workday, NetSuite, and SuccessFactors. The extensions exfiltrated authentication cookies, blocked access to security controls, and enabled complete account takeover through session hijacking. Over 2,300 users installed these extensions before Socket.dev researchers reported them to Google. The most sophisticated variant could inject stolen session tokens directly into attacker-controlled browsers, bypassing login screens and multi-factor authentication entirely.
15 Impressions