North Korean hackers systematically distribute malicious code packages across multiple major package managers and browser ecosystems to compromise developer accounts.
Malicious npm packages impersonate legitimate Rollup polyfills and enable North Korean actors to steal data and gain remote access to developer systems.
Large language models regularly hallucinate non-existent web addresses that attackers preemptively register and abuse with phishing pages; Palo Alto Networks Unit 42 documents the “Phantom Squatting” phenomenon for the first time in practice.
A fake Perplexity extension on the Chrome Web Store was discovered intercepting search queries and browsing data, transmitting them to attackers’ servers.
Attacks on popular AI brands exploit rapid employee trust in new productivity tools and create a governance blind spot in browser extension management.
A fake Perplexity extension in Chrome completely redirected user inputs and search queries to an attacker-controlled server before forwarding the requests.
2.6 million Microsoft Edge users were exposed to malware in 119 hidden browser add-ons – a failure of marketplace validation processes with direct implications for enterprise-wide endpoint controls.
Microsoft removed a steganography-based adware network (StegoAd) consisting of 119 extensions that had been active since at least 2021 and concealed malware payloads in images and fonts.