When you install an extension, it can request permissions that allow it to read or modify webpage content, access your tabs, observe network requests, or interact with information displayed in your browser
A malicious extension can abuse those permissions to collect data from the pages you visit
That could include browsing history, search queries, form data, emails, messages, or other information displayed on a webpage
Now imagine you install a seemingly harmless extension
You open your email
If the extension has permission to access the page, it can potentially read information displayed there
You visit a shopping site and enter your name, address, or other information into a form
The extension can potentially access that information too
You open your bank's website
If it has the necessary permissions, the extension can inspect the page, interact with its content, or inject code into it
Some extensions can also inject JavaScript into websites, allowing them to modify pages or monitor what happens on them
Once the extension collects the information, it can send it to a server controlled by the attacker
And because the extension is running inside your browser, the activity can look like normal browser behavior
That's what makes malicious extensions dangerous
You don't necessarily have to download malware onto your computer
You can install the code yourself, give it access to your browser, and then let it sit there watching the websites you use
Novo Nordisk hackers got in through a GitHub token left in a repo
stayed for two months
took 1.3TB of data including unreleased drug formulas and internal AI models
then asked for $25 million
Novo Nordisk said no
so now they're selling Ozempic's secrets on the dark web
a GitHub token did this