Malicious Chrome Extensions Target Workday, NetSuite, and SAP in Coordinated Enterprise Account Hijacking Campaign

Listen to this Post

Featured Image

Introduction: A Silent Threat Inside the Browser

Enterprise security teams often focus on network defenses, endpoint protection, and cloud posture management. Yet, one of the most trusted tools in daily corporate workflows—the browser—has quietly become a powerful attack surface. A newly uncovered campaign involving malicious Google Chrome extensions shows how attackers can weaponize seemingly legitimate productivity tools to gain deep, persistent access to critical HR and ERP systems. By abusing browser trust, these extensions turned routine account management into an entry point for large-scale enterprise compromise.

Campaign Overview: What Was Discovered

Security researchers have identified a coordinated set of malicious Google Chrome extensions designed to steal cookies, hijack authenticated sessions, and block incident response actions. These extensions specifically targeted widely used enterprise platforms such as Workday, NetSuite, and SAP SuccessFactors. Although the extensions have now been removed from the Chrome Web Store, the damage was already done, with more than 2,300 users installing them before takedown.

The Disguise: Productivity Tools with a Hidden Agenda

The malicious extensions were carefully presented as helpful productivity utilities for professionals managing multiple HR and ERP accounts. Their Chrome Web Store listings appeared polished, professional, and credible. Some even claimed to include security features aimed at protecting accounts from compromise. In reality, these claims were deliberately deceptive, masking the extensions’ true purpose: complete account takeover.

Identified Extensions: Five Names, One Operation

The campaign involved five Chrome extensions: DataByCloud 2, Tool Access 11, DataByCloud Access, Data By Cloud 1, and Software Access. While they were listed as being developed by separate publishers, deeper analysis revealed that they were part of a single, coordinated operation. The naming variations were likely intended to avoid detection and reduce suspicion among users and platform moderators.

Evidence of Coordination: Shared Code and Infrastructure

Researchers found strong indicators linking the extensions together. All five targeted the same enterprise platforms, used identical API endpoint patterns, shared the same security tool detection lists, and exhibited nearly identical code structures. These similarities strongly suggest centralized development and management, despite the appearance of independent publishers.

Initial Infection Vector: Chrome Web Store Trust Abuse

By distributing the extensions through the official Chrome Web Store, attackers exploited a critical trust assumption. Many enterprise users assume that extensions available through Google’s platform have been vetted for safety. This false sense of security significantly increased installation rates and reduced skepticism during onboarding.

Cookie Theft: Stealing Access Without Passwords

Once installed, the extensions immediately began extracting authentication cookies from the browser. These cookies were then uploaded to a command-and-control (C2) server every 60 seconds. Because cookies often represent an already authenticated session, attackers could bypass login credentials and multi-factor authentication entirely.

Session Hijacking: Persistent Account Control

Beyond cookie theft, the extensions extracted session tokens and gained control over session management interfaces. This allowed attackers to maintain long-term access to enterprise accounts. Even if a user logged out or attempted to secure their account, the attackers retained control through stolen session artifacts.

Encrypted Command-and-Control Traffic

To evade detection, the malicious extensions encrypted their communications with C2 servers. This made network-based detection significantly more difficult, especially in environments without deep SSL inspection or advanced behavioral monitoring at the browser level.

Blocking Incident Response: Defense Evasion by Design

One of the most alarming aspects of this campaign was its focus on blocking remediation. The extensions actively interfered with standard incident response workflows, ensuring that stolen access remained valid for as long as possible.

Preventing Password Changes

The malicious code included mechanisms to prevent users from changing their passwords. This ensured that stolen cookies and session tokens remained usable indefinitely, even if a compromise was suspected.

Administrator Lockout Sabotage

When administrators attempted to disable compromised user accounts, they encountered blank pages and redirect loops. This deliberate disruption effectively prevented security teams from taking corrective action, buying attackers valuable time inside enterprise systems.

Enterprise Impact: HR and ERP Systems as Prime Targets

By targeting HR and ERP platforms, attackers positioned themselves for maximum impact. These systems often contain sensitive employee data, payroll information, financial records, and access controls tied to other enterprise services. Compromising them can enable lateral movement, financial fraud, and data exfiltration at scale.

Expert Insight: Why This Attack Matters

According to security researchers, the coordinated deployment of cookie theft, session hijacking, and administrative blocking across multiple extensions represents a highly sophisticated attack. It demonstrates a deep understanding of enterprise workflows, browser security models, and incident response processes.

Anticipated Expansion: Not an Isolated Case

Researchers warned that similar attack patterns targeting other enterprise platforms should be expected. As organizations increasingly rely on browser-based SaaS tools, malicious extensions offer attackers a scalable and low-friction path to high-value targets.

Mitigation Advice: Restricting Extension Installation

To reduce risk, security teams are advised to implement Chrome Enterprise extension allowlists. This approach ensures that only pre-approved extensions can be installed, significantly reducing exposure to malicious or unvetted tools.

Monitoring for Patterns: Behavioral Detection

Organizations should actively monitor for extensions requesting permissions that align with known enterprise platforms. Multiple extensions targeting the same services with similar permission sets should be treated as a red flag and investigated immediately.

Vendor Response: Awaiting Platform Accountability

The malicious extensions have been removed from the Chrome Web Store following disclosure. However, questions remain about detection timelines and preventative controls. Platform providers play a critical role in preventing similar campaigns from reaching thousands of users in the future.

What Undercode Say: Browser Extensions Are the New Supply Chain

Browser extensions have quietly become a shadow supply chain inside enterprises. Unlike traditional software, they often bypass formal procurement and security review processes, yet they operate with powerful permissions over authenticated sessions.

What Undercode Say: Cookie Theft Beats Credential Phishing

This campaign highlights a strategic shift away from phishing passwords toward stealing authenticated session data. Cookies and tokens allow attackers to sidestep MFA, password rotations, and identity verification controls entirely.

What Undercode Say: HR and ERP Systems Offer High Leverage

Targeting HR and ERP platforms is a calculated move. These systems sit at the intersection of identity, finance, and operations, making them ideal launchpads for broader enterprise compromise.

What Undercode Say: Defense Evasion Is Now Built In

The most dangerous evolution seen here is the proactive sabotage of incident response. Attackers are no longer just trying to get in; they are engineering persistence by neutralizing the very controls designed to remove them.

What Undercode Say: Chrome Store Trust Is a Weak Link

The campaign underscores a systemic issue with extension marketplaces. Visual polish and professional descriptions are enough to convince users, even in enterprise environments, to install unverified code with extensive permissions.

What Undercode Say: Allowlisting Is No Longer Optional

Relying on user judgment for extension security is no longer viable. Enterprises must treat browser extensions as software assets, subject to the same governance, approval, and lifecycle management as any other tool.

What Undercode Say: Detection Must Move Into the Browser

Traditional endpoint and network security tools often miss malicious extension behavior. Future defenses must include browser-level telemetry, extension behavior analysis, and real-time session integrity monitoring.

What Undercode Say: Expect More Polished Attacks

As attackers refine these techniques, future malicious extensions will likely appear even more legitimate, including fake reviews, staged update histories, and cloned branding from known vendors.

Fact Checker Results: Verification Summary

✅ The malicious extensions were publicly available on the Chrome Web Store and later removed.
✅ The campaign targeted Workday, NetSuite, and SAP SuccessFactors with coordinated techniques.
❌ No evidence suggests this was an isolated or one-off attack limited to these five extensions.

Prediction: Where This Threat Is Headed

🔮 Browser-based attacks will increasingly replace traditional phishing in enterprise environments.
🔮 SaaS platforms beyond HR and ERP will become primary targets for malicious extensions.
🔮 Extension governance will emerge as a core pillar of enterprise security strategy.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon