Coordinated Chrome extensions harvest enterprise login cookies from Workday, NetSuite, and SAP SuccessFactors

1 min read
Source: BleepingComputer
Coordinated Chrome extensions harvest enterprise login cookies from Workday, NetSuite, and SAP SuccessFactors
Photo: BleepingComputer
TL;DR Summary

Security researchers found five malicious Chrome extensions posing as productivity/security tools for enterprise HR/ERP platforms (Workday, NetSuite, SAP SuccessFactors) that exfiltrate authentication cookies, block security administration pages, and, in one case, inject cookies to hijack active sessions. The campaign, linked by shared infrastructure and targeting patterns, had about 2,300 installations. Extensions were taken down after disclosure; affected users should notify security admins and rotate passwords on the targeted platforms.

Share this article

Reading Insights

Total Reads

0

Unique Readers

14

Time Saved

4 min

vs 5 min read

Condensed

93%

95869 words

Want the full story? Read the original article

Read on BleepingComputer