Chrome Extension Supply Chain Compromised at Industrial Scale — Audit Your Fleet Today
The Threat
Researchers identified more than 300 malicious Chrome extensions with a combined 37.4 million downloads. This is not a theoretical supply chain risk — it's active exfiltration happening right now across enterprise environments. The breakdown is stark:
| Extension Category | Count | Primary Capability | Data Exfiltrated |
|---|---|---|---|
| General malicious | 300+ | Iframe injection, data theft | Browsing history, user data |
| Immediate history exfil | 153 | History exfiltration on install | Full browsing history |
| AI-disguised (LayerX) | 30 | Gmail content extraction | Email content to C2 servers |
| Gmail-targeting subset | 15 | Email content theft | Email body, attachments |
The 153 extensions confirmed to exfiltrate browser history immediately upon installation are the most dangerous — attackers harvest internal URLs, SaaS application paths, session tokens in URL parameters, and browsing patterns that reveal organizational structure. A separate LayerX report identified 30 extensions disguised as AI productivity tools sharing identical backend infrastructure, with 15 specifically targeting Gmail to extract email content and transmit it to third-party servers.
Why AI Disguises Make This Worse
The AI-tool disguise is particularly effective because users actively seek these extensions and grant them broad permissions. Gmail targeting means MFA codes sent via email, internal communications, sensitive attachments, and calendar data are all compromised. Browser history exfiltration reveals your internal tooling landscape to attackers — every Jira URL, every Confluence path, every internal dashboard.
Browser extensions with 37.4 million installs are exfiltrating your browsing history and Gmail content right now — the only question is whether any of them are on your managed fleet.
Defensive Actions
This requires same-day response. Pull your managed fleet's extension inventory via Chrome Enterprise policies. Cross-reference against published IOCs from the campaign. Enforce extension allowlisting immediately — block any extension requesting history, tabs, or Gmail read permissions that isn't explicitly approved. Monitor for anomalous network traffic from browser processes to unknown domains as your primary detection signal.
What to do
Pull complete Chrome extension inventory across all managed endpoints and cross-reference against published IOCs from the 300+ extension campaign
Enforce Chrome Enterprise extension allowlisting, blocking all extensions requesting history, tabs, or Gmail read permissions not on your approved list
Deploy network monitoring rules to detect browser process connections to unknown C2 domains identified in the LayerX report