Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Interview: Shopify CISO Andrew Dunbar on Securing an E-Commerce Giant

June 26, 2026

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Malicious Google Chrome Extensions Hijack Workday and Netsuite
News

Malicious Google Chrome Extensions Hijack Workday and Netsuite

Team-CWDBy Team-CWDJanuary 19, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A set of malicious Google Chrome Extensions which steal cookies, takeover accounts and actively block incident response have been identified targeting widely used human resource (HR) and enterprise resource planning (ERP) platforms, including Workday, Netsuite and SAP SuccessFactors.

Identified by the threat research team at application security firm Socket, the extensions posed as productivity tools for users managing multiple HR and ERP accounts and were available in the Chrome Web Store.  

Following disclosure, the malicious extensions have been removed, but not before they were downloaded by 2300 users.

The extensions were named DataByCloud 2, Tool Access 11, DataByCloud Access, Data By Cloud 1 and Software Access.

Researchers noted that the extensions all targeted the same enterprise platforms and shared identical security tool detection lists, API endpoint patterns and code structures, indicating a coordinated operation despite the extensions having been listed as developed separate publishers.

The Chrome Web Store listings were designed to look polished and professional. Some even claimed they contained security features to prevent account compromise, despite the fact that compromising accounts was their actual goal.

Once installed, the malicious extensions engaged in a range of actions to take control of accounts. This included extracting authentication cookies and uploading them to a command and control (C2) server every 60 seconds, as well as extracting session tokens, encrypting C2 traffic and the ability to take control of session control interfaces.

The extensions were also designed to actively prevent incident response actions against them. Techniques deployed included preventing passwords being changed to help ensure stolen access tokens remained valid indefinitely and preventing security teams from locking out compromised accounts during remediation.

In another trick designed to help prevent response capabilities, administrators attempting to disable an affected user’s account would encounter a blank page and redirect loop.

“The coordinated deployment of cookie theft, administrative blocking, and session hijacking across five extensions represents a sophisticated attack on enterprise HR and ERP platforms,” said Kush Pandya,  security engineer and researcher at Socket

“Similar patterns targeting other enterprise platforms should be anticipated,” he added.

To prevent accounts being compromised by this or similar malicious campaigns, Socket said that security teams should implement Chrome Enterprise extension allowlists to prevent installation of unauthorized extensions.

Socket also recommended that orgnaizations monitor for extensions targeting the same enterprise platforms with similar permission requests.

Infosecurity has contacted Google for comment.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution
Next Article Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How to tell if a voice call is AI or not

February 23, 2026

Look out for phony verification pages spreading malware

September 14, 2025

Beware of threats lurking in booby-trapped PDF files

October 7, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.