Coordinated Chrome Extension Malware Targets Enterprise HR and ERP Platforms

Listen to this Post

Featured Image
A sophisticated malware campaign has emerged, exploiting Chrome extensions to attack enterprise HR and ERP systems such as Workday, NetSuite, and SAP SuccessFactors. Researchers from Threat Research Team have uncovered a coordinated operation involving five malicious extensions that collectively target over 2,300 users, aiming to steal authentication tokens, block administrative controls, and hijack accounts entirely.

These extensions disguise themselves as productivity tools, promising easier multi-account management and improved access to enterprise platforms. However, beneath this facade, they quietly exfiltrate credentials, manipulate browser cookies, and disable security features. Four extensions operate under the publisher name databycloud1104, while the fifth, Software Access, uses different branding but shares the same command-and-control infrastructure.

Each extension requests seemingly harmless permissions, while privacy policies falsely claim no data collection. Attackers maintain persistence through sophisticated mechanisms such as cookie monitoring every 60 seconds, DOM manipulation to block administrative pages, and anti-debugging measures that prevent code inspection. The most advanced extension, Software Access, performs bidirectional cookie injection, allowing attackers to bypass multi-factor authentication entirely.

The malware actively monitors other security-focused Chrome extensions like EditThisCookie and ModHeader to assess potential interference. The combined effect is devastating: administrators are blocked from rotating credentials, removing trusted devices, or enforcing security policies. Even sandbox environments, like Workday’s testing platform, are affected, forcing organizations to either risk deploying untested security changes or abandon them entirely.

Users and organizations are urged to immediately remove these extensions, audit authentication logs for suspicious activity, disable Chrome sync to prevent automatic reinstallation, and enforce extension allowlists through Chrome Enterprise policies. Indicators of compromise include the publisher names, extension IDs, command-and-control domains, and targeted cookies. The malware employs MITRE ATT&CK techniques such as web session cookie theft, browser session hijacking, and tool modification to maintain persistent access. Google’s Chrome Web Store has been notified for takedown, but vigilance is necessary as attackers may reuse infrastructure across multiple campaigns.

What Undercode Say:

This campaign highlights a dangerous evolution in enterprise-targeted attacks. By leveraging widely trusted Chrome extensions, attackers bypass traditional defenses like endpoint monitoring or MFA protections. The combination of persistent cookie exfiltration, DOM manipulation, and anti-debugging measures shows a high level of sophistication. Unlike typical malware, which relies on endpoint infection, this campaign exploits browser-level vulnerabilities, effectively making the user’s own environment the attack vector.

Blocking administrative interfaces in sandbox environments is particularly concerning. Security teams rely on these controlled platforms to validate policy changes and security improvements before production deployment. By obstructing these workflows, attackers force organizations into a dilemma: deploy untested security measures or delay critical updates, both of which increase operational risk.

The campaign also demonstrates complementary attack synergy. Each extension performs a specific role—cookie exfiltration, interface blocking, or direct session hijacking—while sharing intelligence about the victim environment and installed defenses. This modular approach is efficient, scalable, and remarkably stealthy.

From an operational security standpoint, organizations must move beyond traditional antivirus and SIEM monitoring. Extension allowlists, careful auditing of active sessions, and blocking outbound connections to suspicious C2 domains are critical defenses. Security teams must also account for sophisticated anti-forensic tactics such as DOM mutation observers, developer tools blocking, and automated credential monitoring.

Attackers targeting enterprise platforms may continue evolving, incorporating artificial intelligence to automate monitoring of session tokens and user behavior. Threat intelligence sharing across organizations becomes critical, as each new discovery, like databycloud1104 or Software Access, informs protective measures for other platforms. The reuse of publisher infrastructure across multiple extensions suggests a long-term, adaptable adversary strategy rather than a one-off campaign.

The financial and operational impact could be severe. Organizations may face credential compromise, regulatory penalties, downtime in critical HR/ERP operations, and potential insider-like access by attackers. Prevention, rapid detection, and incident response are paramount, as standard remediation actions—like password resets or disabling accounts—can be neutralized by the malware itself.

Enterprises should implement layered security: browser policy enforcement, rigorous extension monitoring, and proactive intelligence collection. Only by understanding the attack lifecycle—cookie theft, monitoring, interface obstruction, and session hijacking—can organizations respond effectively.

Fact Checker Results:

✅ Malware campaign confirmed to target Workday, NetSuite, and SAP SuccessFactors.
✅ Five Chrome extensions identified, with both cookie exfiltration and admin interface blocking capabilities.
✅ MITRE ATT&CK mapping validated (T1539, T1185, T1176.001, T1027, T1562.001).

Prediction:

The next wave of enterprise malware will likely combine browser-based attacks with AI-driven monitoring, making session hijacking more dynamic and harder to detect. 🛡️ Organizations that implement strict extension allowlists, continuous session auditing, and network-level C2 blocking may remain ahead. ⚠️ Enterprises ignoring browser-level security may face persistent account compromises and operational paralysis in HR and ERP systems. 💻

If you want, I can also create a visual attack flow diagram showing how these five extensions interact and hijack enterprise accounts—it would make this article even more compelling for security teams. Do you want me to do that?

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon