Annex Security

76 posts

Annex Security banner
Annex Security

Annex Security

@secureannex

Discover what is hiding in your software extensions

Katılım Temmuz 2024
5 Takip Edilen263 Takipçiler
Annex Security retweetledi
tuckner
tuckner@tuckner·
A Chrome extension with 7,000 users and a Google Featured badge was recently sold, weaponized, and pushed a malicious update to that executed code through a hidden pixel. Here's how it worked 👇
tuckner tweet media
English
5
82
363
37.5K
Annex Security retweetledi
tuckner
tuckner@tuckner·
🧨 New CrashFix techniques found in browser extensions. "Pixel Shield" — a fully functional ad blocker (4.7 stars, 561 users) because it is a uBlock Origin clone. Hidden inside: a "Promise Bomb" that creates 10 MILLION unresolvable promises to crash your browser on command.
tuckner tweet media
English
1
18
94
13.1K
Annex Security retweetledi
tuckner
tuckner@tuckner·
This report contains 287 browser extensions tracking 37 million+ users. These were identified using methodology of sandboxing extensions, automatically browsing to URLs, and measuring a data ratio transferred. Real companies, fake services, well established, it's a mixed bag.
tuckner tweet media
English
2
36
185
49.9K
Annex Security retweetledi
tuckner
tuckner@tuckner·
The next supply chain worm has been seeded in Open VSX. A cloned Angular extension with 5000 downloads has been available for two weeks and was updated with malware 6 days ago. This multi stage attack uses etherhiding, gcal c2, rust implants, and more. annex.security/blog/worms-lur…
English
2
9
49
10.2K
Annex Security
Annex Security@secureannex·
RT @tuckner: Great work by the Obsidian Security team exfiltrating ChatGPT API keys to Telegram. I heard there's more to come! https://t.c…
English
0
1
0
123
Annex Security retweetledi
tuckner
tuckner@tuckner·
A browser extension with over a million users is poaching the prompts of leading AI chat tools. SimilarWeb loads obfuscated remote configuration to collect the prompts, responses and metadata of your conversations. Your private thoughts are analytics companies gain. secureannex.com/blog/prompt-po…
English
0
6
23
6K
Annex Security retweetledi
Trust Wallet
Trust Wallet@TrustWallet·
We’ve identified a security incident affecting Trust Wallet Browser Extension version 2.68 only. Users with Browser Extension 2.68 should disable and upgrade to 2.69. Please refer to the official Chrome Webstore link here: chrome.google.com/webstore/detai… Please note: Mobile-only users and all other browser extension versions are not impacted. We understand how concerning this is and our team is actively working on the issue. We’ll keep sharing updates as soon as possible.
English
821
903
3.1K
2.9M
Annex Security retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
Glassworm's resurgence | by @secureannex @tuckner "we've identified and tracked an unprecedented 23 extensions which copy other popular extensions, update after publishing with malware, manipulate download counts, and use KNOWN attack signatures which have been in use for months" secureannex.com/blog/glassworm…
English
1
6
42
6.2K
Annex Security retweetledi
tuckner
tuckner@tuckner·
Glassworm returned in a big way during the holiday. We're tracking 23 code extensions across the VS Marketplace and Open VSX which copy popular extensions, evade filters, manipulate their download counts, and then update with sinister malware. secureannex.com/blog/glassworm…
English
0
8
18
2.3K
Annex Security retweetledi
tuckner
tuckner@tuckner·
The extension was approved, now what? Are you going back tomorrow to see if it changed? You know they auto update instantly right? Rolling out to Secure Annex - code change alerts. This takes comparison of the code from the previous version along with additional context to understand how the code in an extension is changing over time.
tuckner tweet media
English
0
4
9
2K
Annex Security retweetledi
tuckner
tuckner@tuckner·
A brand new unlisted extension with 100,000 users? 41 ratings? Must be really valuable. Nope - completely manipulated stats and it doesn't even contain real code. It exists only to collect your searches and earn Bing Rewards.
tuckner tweet mediatuckner tweet media
English
3
7
178
14.1K
Annex Security retweetledi
tuckner
tuckner@tuckner·
We've found code extensions openly call themselves malware in the VS Code marketplace recently and now browser extensions posing as known malicious remote access tools to the Chrome Web Store. What gives?
tuckner tweet media
English
0
1
10
933
Annex Security retweetledi
tuckner
tuckner@tuckner·
Another edition of "Guess the right solidity". Two of these will compromise your machine the moment you hit install.
tuckner tweet media
English
30
31
523
74.9K
Annex Security retweetledi
tuckner
tuckner@tuckner·
Powerful new Detections are added to Secure Annex. These are already catching subtle exploits like unicode extension names that evade other filters, manipulated download counts, and combinations of suspicious signatures in code.
tuckner tweet media
English
0
1
3
476