Postări

Se afișează postări cu eticheta supply chain attack

Browser Extension Supply Chain Attacks: Protecting Hosting Admins and Server Credentials

Attackers are quietly turning trusted browser extensions into malware after acquiring them from legitimate publishers or pushing malicious updates, according to new research from Socket. The campaign, spanning 19 Chrome and Edge add-ons, highlights a systemic supply-chain risk for anyone who manages web hosting, VPS, or cloud infrastructure through a browser. For hosting buyers, sysadmins, and WordPress site owners, the danger is direct: extensions that capture form input and authentication tokens can siphon credentials used in control panels, FTP clients, and cloud consoles. Because browser extensions auto-update silently, a tool deemed safe last month can become a credential-harvesting backdoor today. This article breaks down the campaign, explains why infrastructure operators are exposed, and outlines practical containment and hardening steps. For a more detailed walkthrough of this part of the topic, read Bitwarden CLI Compromised in Supply Chain Attack - What Happened and What t...