Malicious Chrome extensions are posing as productivity and security tools for enterprise HR and ERP platforms and steal credentials or block admin pages used to address security incidents. The campaign was discovered by cybersecurity firm Socket, which identified five Chrome extensions targeting Workday, NetSuite, and SAP SuccessFactors (with more than 2,300 downloads in total).

“The campaign implements three distinct attack types: cookie export to remote servers, DOM manipulation to block security management pages, and two-way cookie injection for direct session hijacking,” Socket reports. The extensions target the same enterprise platforms and share identical security tool detection lists, API endpoint patterns, and code structures, suggesting a coordinated operation despite appearing to be separate publishers. The Chrome extensions were published under different names, but researchers say they share identical infrastructure, code patterns, and targeting.
See also: Admin accounts: The most dangerous target on a corporate network
Malicious Chrome Extensions: A Coordinated Operation
Four of the extensions were published under the developer name databycloud1104, while the fifth used a different name (Software Access). Although the extensions only affected 2,300 users, the theft of business could fuel ransomware attacks and large-scale data theft.
Socket says the extensions were promoted to users of enterprise HR and ERP platforms, presenting themselves as tools designed to improve productivity, streamline workflows or strengthen security controls. Several of the Chrome extensions claimed to offer simplified access to “premium tools” for Workday, NetSuite and other platforms.

One of the most popular extensions, Data By Cloud 2, was installed 1,000 times and promoted as a dashboard that offers bulk management tools and faster access for users managing multiple business accounts.
Another extension, Tool Access 11, was positioned as a security-focused add-on that would restrict access to sensitive administrative functions. Its listing claimed that the extension could limit user interactions with “special tools” to prevent account compromise.
See also: DocuSign, Microsoft, Google: Why brands are the ultimate weapon for phishers
Other extensions used similar language about providing “access” to tools and services, requesting permissions that seemed consistent with business integrations.
However, Socket says that none of the extensions mentioned cookie extraction, credential extraction, or blocking security management. The privacy policies for the extensions also did not mention that user data would be collected.
How malicious extensions work
Socket's analysis of the extensions found that they used a mix of malicious behavior, including exporting authentication cookies, blocking admin pages , and session hijacking via cookie injection. Multiple extensions consistently exported authentication cookies named “__session” for a targeted domain, containing active login tokens for Workday, NetSuite, and SuccessFactors.
These tokens were exported every 60 seconds to remote command and control servers, allowing attackers to maintain access even when users logged out and reconnected.
Two extensions, Tool Access 11 and Data By Cloud 2, blocked access to security and incident response pages within Workday. Using page title detection, the Chrome extensions either deleted the content on the pages or redirected administrators away from the admin pages.

“Tool Access 11 targets 44 administrative pages, including authentication policies, security proxy configuration, IP range management and session controls,” Socket explains.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“Data By Cloud 2 targets 56 pages by adding password management, account deactivation, 2FA checks, and security audit logs“.
Blocking access to these pages could prevent legitimate administrators from responding to security incidents if one is detected.
See also: Google Vertex AI security clearances amplify insider threats
According to Socket, the Software Access extension implemented the most malicious behavior, as it also contains a function that allows bidirectional cookie manipulation. This means that in addition to stealing session tokens, it is also possible to download stolen cookies from the attacker's server and insert them directly into a browser.
By setting authentication cookies through the C2, attackers could take control of authenticated sessions without entering usernames, passwords, or multi-factor authentication codes.
According to Socket, this technique allowed for direct account theft on targeted corporate platforms.
The company reported the Chrome extensions to Google, and at the time of publishing this article, they appear to have been removed.
Anyone who used these extensions should report them to their security administrators for further incident response and change their passwords on the targeted platforms.
Source: www.bleepingcomputer.com
