PALO ALTO, Singapore, March 6, 2025/CyberNewsWire/--With recent disclosures of attacks such as Browser Syncjacking and information-stealing extensions, browser extensions have become a major security concern for many organizations.
SquareX's research team has discovered a new class of malicious extensions capable of impersonating any other extension installed in the victim's browser, including password managers and cryptocurrency wallets.
These extensions can modify their interface, icons, and texts to exactly mimic a legitimate extension, tricking users into entering credentials and sensitive information.
The attack affects major browsers, including Chrome and Edge. Polymorphic extensions exploit the fact that most users interact with extensions through pinned icons in the browser toolbar.
The process begins when the user installs a malicious extension that disguises itself, for example, as a harmless artificial intelligence tool. To make the attack even more convincing, the extension offers the promised functionality and remains inactive for a certain period.
Meanwhile, the malicious extension analyzes which other extensions are installed and, once identified, completely changes its appearance to mimic its target, including the icon displayed in the toolbar.
Additionally, it can temporarily disable the real extension, removing it from the pinned toolbar. Since most users use these icons as a visual reference, changing the icon may be enough to convince them they are interacting with the legitimate extension.
Even if the user checks the browser's extension panel, there is no clear way to correlate the displayed tools with the pinned icons. To avoid suspicion, the malicious extension can even temporarily disable the original extension to ensure only its icon is present.
Most concerning is that these polymorphic extensions can impersonate any browser extension. For example, they can mimic popular password managers to trick users into revealing their master key, allowing attackers to access all stored credentials.
Similarly, they can replicate cryptocurrency wallets and use stolen credentials to authorize transactions and transfer funds to attackers.
Other potential targets include developer tools and banking extensions, which could provide unauthorized access to applications storing sensitive data or financial assets.
This attack only requires medium-risk permissions according to the Chrome Store classification. Ironically, many of these permissions are used by password managers and popular tools like ad blockers and page customizers, making it even harder to identify malicious intent by analyzing the extension's code alone.
SquareX founder Vivek Ramachandran warns that 'Browser extensions pose a major risk to businesses and users. Unfortunately, most organizations have no way to audit their own extension ecosystem and verify if they are malicious. This emphasizes the need for a native browser security solution, similar to what an EDR is for operating systems.'
These polymorphic extensions exploit existing features in Chrome to carry out the attack. This means there is no software vulnerability involved and therefore cannot be resolved with a patch. SquareX has contacted Chrome to recommend banning or implementing alerts for icon changes or abrupt HTML modifications, as these methods can be easily used by attackers.
For businesses, static extension analysis and permission-based policies are no longer sufficient. It is essential to have a security tool integrated into the browser that can dynamically analyze extension behavior at runtime, including polymorphic trends of malicious extensions.
At Q2BSTUDIO, we understand the importance of cybersecurity in the digital age and work to develop innovative solutions that protect businesses against advanced threats. As a development and technology services company, we offer tools and strategies to ensure the security of applications and digital platforms, providing protection against sophisticated attacks like those described in this report.
For more information about our security and technology solutions, visit Q2BSTUDIO.




