threat-intel Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found A popular Chrome and Edge header-editing extension, ModHeader, was found to contain a hidden browsing history collector, despite claims it didn't collect data. Researchers at Stripe OLT discovered the collector was dorma… The Hacker News · Jul 13, 2026 High CNextensiondata-collectionheader-editing
malware Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses A new browser extension campaign, dubbed Silent Swap by McAfee Labs, is targeting cryptocurrency users by stealthily replacing wallet addresses during transactions. The malicious extension, disguised as a Google Notes ut… The Hacker News · Jun 30, 2026 High INUSBRclipboardwalletcrypto
malware Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input A malicious Chrome extension disguised as the Perplexity AI search engine was discovered by Microsoft, intercepting user searches and address bar input. The extension secretly logged this data by routing it through an at… The Hacker News · Jun 29, 2026 High chromeextensiondata collection
threat-intel Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability A popular Google Chrome ad blocker extension, Adblock for YouTube, with over 10 million installs, has been found to contain a dormant script injection capability. Researchers discovered the extension’s architecture allow… The Hacker News · Jun 25, 2026 High USadblockjavascriptprivacy
supply-chain GitHub links repo breach to TanStack npm supply-chain attack A supply-chain attack targeting GitHub originated with a malicious version of the Nx Console VS Code extension, facilitated by the TeamPCP threat group. The attack compromised over 3,800 internal repositories and extende… BleepingComputer · May 21, 2026 High USsupply-chainnpmvscode
supply-chain GitHub confirms breach of 3,800 repos via malicious VSCode extension GitHub experienced a breach affecting approximately 3,800 internal repositories after an employee installed a malicious VS Code extension. The incident is linked to a broader supply chain attack by TeamPCP, who are deman… BleepingComputer · May 20, 2026 High supply chainvscodeextension