browser extensions3 articles
KREMLIN Malware Uses Ethereum Smart Contracts and Rogue Browser Extensions to Drain Brazilian Bank Accounts
KREMLIN is a Brazilian banking malware ecosystem, tracked by Elastic Security Labs since at least May 2025, that uses multi-stage JavaScript loaders and malicious browser extensions to steal credentials, session tokens, and sensitive data from victims impersonating customers of over a dozen Brazilian banks. A key feature of the operation is its use of Ethereum smart contracts to dynamically update command-and-control infrastructure, making it highly resilient to disruption. The malicious browser extensions bypass Chromium's security mechanisms to harvest cookies, screenshots, and browsing data, with over 1,500 infected systems identified — more than 98% located in Brazil.
The 5% Problem: Why Your AI Power Users Are Your Biggest Security Headache
New research from Akamai reveals that the top 5% of enterprise AI "power users" interact with AI tools at 12 times the rate of average employees, creating disproportionate security risks through shadow AI, data leakage, and unvetted autonomous tools operating outside corporate oversight. Nearly half of all enterprise AI conversations occur through personal rather than corporate-managed accounts, and 16% of AI browser extensions contain known security vulnerabilities, expanding the attack surface significantly. Security teams are urged to shift focus from broadly policing mainstream AI tools to identifying where AI is most deeply embedded in operations and whether those systems fall within established guardrails.
77 Firefox Add-ons Caught Running a Coordinated Crypto Wallet Heist
Forty malicious Firefox extensions have been discovered impersonating legitimate Web3 products like OKX and Rabby Wallet as part of a campaign called "Offside Wallet Theft Factory," believed to have been active since March 2026. The extensions steal cryptocurrency wallet secrets — including recovery phrases and private keys — using methods such as fake wallet pages, hidden malicious code, and exfiltration via Cloudflare Workers and Supabase. Some extensions initially appeared as innocent sports score or utility tools before being repurposed as wallet-stealing malware, with researchers noting that the low cost of repeatedly publishing disposable extensions makes the campaign highly scalable and persistent.