If you asked most small business IT managers to list every browser extension installed across their fleet right now, they couldn't do it. Extensions get installed with a click, sync across devices via employee Google or Microsoft accounts, and rarely show up on any inventory list. That blind spot is exactly what attackers are counting on — and it's no longer theoretical.
Malware Is Actively Harvesting Chrome Extension Storage
According to The Hacker News, a stealer called WeaselBiscuit is spreading through 13 malicious npm packages and specifically targets Chrome's extension storage to harvest credentials and session data. This isn't a generic infostealer grabbing whatever it can find — it's purpose-built to dig into the exact place where password managers, session tokens, and autofill data often live inside browser extensions.
That matters because browser extensions frequently have far more access than employees realize. Many request permission to read and modify data on every website visited, which means a compromised or malicious extension can quietly capture logins, session cookies, and sensitive form data without ever touching the endpoint's operating system.
The Browser Is Becoming the Whole Attack Surface, Not Just Extensions
Extensions are only part of the problem. A separate finding highlighted by security researchers describes the BragJack attack, which shows that browser-integrated AI assistants can themselves be hijacked and turned against the user — accessing sensitive information and exfiltrating it through the browser's own agentic AI features. Between rogue extensions and manipulated AI assistants, the browser itself has quietly become one of the largest unmonitored attack surfaces in a small business environment.
Making matters worse, the barrier to building these tools is dropping fast. Per The Hacker News, a threat actor claiming to be a bug bounty hunter appears to have used an LLM to build the PhantomRaven npm stealer — another JavaScript-based credential harvester distributed through developer package ecosystems. The same delivery mechanism that spreads through npm packages is increasingly the same pipeline that ends up compromising browser extensions and developer tooling on employee machines. You don't need a nation-state actor anymore; you need one unvetted npm dependency or one convincing extension listing.
Why This Is a Shadow IT Problem, Not Just a Malware Problem
Extensions are shadow IT in disguise. Employees install a PDF converter, a grammar checker, a coupon finder, or a productivity tool without ever asking IT — and each one is a third-party piece of code with broad permissions running inside a trusted session. This is the same root cause we cover in our post on the shadow IT crisis: tools get adopted faster than they get reviewed, and by the time IT notices, the tool is already embedded in daily workflows.
Your Browser Extension Audit Checklist
- Inventory every extension across every managed browser. Use your RMM or browser admin console (Chrome Enterprise, Edge for Business, Google Workspace admin) to pull a full list per device — don't rely on employees self-reporting.
- Flag extensions with broad permissions. Anything requesting "read and change all your data on all websites" deserves a second look, especially if it's not from a verified publisher.
- Check install source and publisher reputation. Extensions with vague descriptions, few reviews, or recently transferred ownership are common vectors for supply-chain-style takeovers.
- Cross-reference against your approved software list. If it's not documented, treat it the same way you'd treat any unauthorized agent — as covered in our guide on detecting unauthorized software and rogue agents.
- Push a browser policy that blocks unmanaged installs. Use group policy or your endpoint management tool to restrict extension installation to an approved allowlist going forward.
- Revoke and remove anything unverified immediately, then re-audit quarterly — extensions update silently and permissions can change after install.
If your organization is pursuing CMMC Level 1 or similar frameworks, this kind of endpoint hygiene control is exactly the type of documented, repeatable process auditors look for, and it pairs well with the access-control discipline outlined in our offboarding checklist for revoking access — the same logic of least-privilege access applies to what runs inside your browsers, not just who has login credentials.
Take Action
Browser extensions, npm packages, and AI-integrated tools are converging into one messy, fast-moving attack surface — and most small businesses find out they had a problem only after a breach. Proactive scanning catches these gaps before attackers do, not after. Oscar Six Security's Radar scan is an affordable way to get visibility into your exposed attack surface for just $99 — check it out at our solutions page.
Focus Forward. We've Got Your Six.