this post was submitted on 09 Dec 2025
32 points (100.0% liked)

Cybersecurity

8776 readers
8 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
top 2 comments
sorted by: hot top controversial new old
[โ€“] x00z@lemmy.world 6 points 4 days ago

A big problem in the whole third party extension world (for browsers and apps like these) is that the creators of these extensions are often swayed to sell their creation. Dropping an infostealer to 1000 people could easily get you 10s of thousands of dollars if you use the stolen info for stuff like bank fraud. So invest a few thousand of that to buy the extension and you get a profit. You can even get access to the accounts of extension creators by getting them infected by other extensions. This can even be automated in the form of a worm such as the NPM malware named Shai-Hulud.

It's an extremely dirty battle that requires every developer to be vigilant about who they trust and to defend their creation at all costs. Easy money always has a bad side, and I hope every developer understands that their users have put a trust into them that the developer has most likely also put into other developers.

Why is it the extensions you most suspect? /s