A security researcher identified 40 malicious Chrome extensions collectively installed by approximately 21.9 million users, documenting capabilities including credential theft, traffic exfiltration, affiliate link injection, and undisclosed data collection. The analysis found 7 extensions actively transmitting data and 33 containing malicious code not observed firing during testing, with common offenses including full-URL exfiltration, fingerprinting, and unauthorized telemetry.
A security research paper documents malicious intermediary attacks on LLM supply chains, revealing how compromised routers can inject malicious tool calls, steal credentials, and enable unauthorized access to government entities and major firms. The researchers demonstrate poisoning techniques affecting dozens of routers and hundreds of hosts, with documented financial losses.