Listen to this Post

In a startling cybersecurity revelation, researchers have uncovered a new wave of malicious Google Chrome extensions designed to target enterprise users. Disguised as popular human resources (HR) and enterprise resource planning (ERP) tools such as Workday, NetSuite, and SuccessFactors, these extensions can completely hijack user accounts without leaving obvious traces. The discovery highlights the growing sophistication of browser-based attacks, where even familiar productivity tools can become gateways for cybercrime.
Malicious Extensions and Their Reach
Cybersecurity firm Socket Security, led by researcher Kush Pandya, has identified five dangerous extensions:
DataByCloud Access – 251 installs
Tool Access 11 – 101 installs
DataByCloud 1 – 1,000 installs
DataByCloud 2 – 1,000 installs
Software Access – 27 installs
All except Software Access have been removed from the official Chrome Web Store but remain accessible on third-party platforms such as Softonic. These extensions are marketed as productivity boosters offering premium access to platforms like Workday and NetSuite. Some of them date back to August 2021, suggesting a long-running, coordinated operation.
How the Extensions Operate
The extensions work by stealing authentication cookies, blocking security and administrative pages, and hijacking sessions. They manipulate the Document Object Model (DOM) to hide security interfaces and exfiltrate sensitive session data to attacker-controlled servers. For instance, DataByCloud Access periodically sends cookies to api.databycloud[.]com, while Tool Access 11 blocks access to 44 critical administrative pages on Workday, effectively neutralizing incident response capabilities.
DataByCloud 2 extends this functionality to 56 pages, covering password resets, account deactivation, 2FA management, and audit logs. DataByCloud 1 enhances stealth by preventing code inspection using the DisableDevtool library and encrypting command-and-control traffic. The most advanced, Software Access, can inject stolen cookies into an attacker’s browser, enabling direct session hijacking and bypassing login security entirely.
Coordinated Attack and Anti-Detection Measures
All five extensions monitor for the presence of 23 security-related Chrome tools, including EditThisCookie, Cookie-Editor, ModHeader, Redux DevTools, and SessionBox. This indicates a deliberate attempt to evade detection and ensure uninterrupted cookie harvesting. Researchers note that the repeated use of similar extension IDs points to either a single threat actor operating under multiple publishers or a common toolkit employed across campaigns.
Recommended Actions for Users
Users who may have installed these extensions are urged to remove them immediately. Organizations should enforce password resets, monitor for unusual login activity, and check for unauthorized access from unknown IP addresses or devices. Failure to act could leave enterprise accounts vulnerable to ongoing stealthy exploitation.
What Undercode Says:
The Scale of Threats in Enterprise Browsers
These extensions represent a significant escalation in browser-based attacks. Traditional security solutions often focus on network-level threats, leaving users exposed to attacks that exploit trusted browser interfaces. The fact that these malicious tools are disguised as widely used HR and ERP applications is especially dangerous for enterprises where users regularly access sensitive corporate data.
Coordinated Attack Patterns
The identical behavior and infrastructure across different extensions suggest a highly coordinated campaign. The attackers’ use of cookie theft, DOM manipulation, and session hijacking indicates a sophisticated understanding of enterprise workflows and browser vulnerabilities. By blocking administrative pages and security interfaces, they effectively render IT teams powerless to respond through normal channels, highlighting the need for proactive threat detection.
Evolution of Browser Exploits
Unlike typical malware that requires user interaction, these extensions operate silently once installed. They continuously siphon authentication tokens and monitor for defensive tools, showing a level of automation and resilience that makes them harder to detect and remove. This evolution in attack methodology points to a future where browser-based threats could rival traditional endpoint malware in impact and complexity.
Implications for Enterprise Security Policy
Enterprises must rethink browser security policies, including restricting the installation of third-party extensions, monitoring browser activity for unusual behaviors, and implementing strict authentication and session management protocols. Employee awareness programs are also crucial, emphasizing that not all productivity tools are safe simply because they appear in official stores.
Persistence and Long-Term Risk
The discovery that some extensions have been active since 2021 underscores the long-term risk these campaigns pose. Even if removed from official channels, they continue to circulate through third-party sites, emphasizing the need for comprehensive threat intelligence and continuous monitoring to prevent recurring exposure.
Privacy and Regulatory Concerns
Exfiltrating cookies and account data can have serious privacy and compliance implications. Companies using these affected platforms could face regulatory scrutiny if user data is compromised, particularly in regions with strict data protection laws like the EU and California.
Lessons for Users and Security Teams
This case highlights the critical need for multi-layered defenses, including browser isolation, enhanced monitoring of session tokens, and active auditing of installed extensions. Traditional antivirus and endpoint detection tools are insufficient alone, and organizations must adopt proactive detection strategies to identify malicious browser behaviors before they escalate.
The Role of Threat Intelligence
Tracking patterns like those seen with DataByCloud and Software Access allows security teams to anticipate attacker behavior. Sharing intelligence on extension-based attacks across industries could prevent similar campaigns from proliferating, highlighting the importance of collaborative cybersecurity measures.
🔍 Fact Checker Results
✅ Verified: Extensions disguised as HR/ERP platforms can steal cookies and hijack sessions.
✅ Verified: DataByCloud 1 and 2 were first published in August 2021.
❌ Misconception: All malicious extensions were removed from the Chrome Web Store—some remain on third-party sites.
📊 Prediction
If organizations fail to implement stricter browser policies and proactive monitoring, these types of attacks will continue to increase in frequency and sophistication. Future campaigns may combine cookie theft with ransomware or espionage, potentially targeting high-value enterprise accounts. Companies that rely heavily on cloud-based HR and ERP tools should anticipate a surge in similar attacks and prepare layered defenses including endpoint monitoring, employee training, and zero-trust session management.
This version emphasizes the real-world danger, provides a clear narrative, and offers in-depth analysis for both technical and executive audiences.
If you want, I can also create a shorter, high-SEO version with punchy headings suitable for a tech news site while retaining all key details. Do you want me to do that?
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




