Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 5 › IT Vendor News › Akamai Technologies

When Productivity Extensions Become Attack Platforms

Akamai Technologies, Wednesday, September 30th, 2026

Akamai's LayerX researchers expose 32 malicious Chrome and Edge extensions that spy on users and commit affiliate fraud via remote configs.

LayerX Research, now part of Akamai, found a coordinated campaign of 32 malicious browser extensions in the Chrome Web Store and Microsoft Edge Add-ons Store affecting more than 6,150 users.

The extensions posed as productivity utilities such as text counters, note-taking apps and YouTube enhancers while harvesting data and monitoring browsing, and near-identical codebases and Korean-language artifacts tie the cluster to a single threat actor.

Remotely hosted configuration files let operators manipulate navigation and run affiliate fraud without pushing updates through store review, and Akamai advises removing extensions with broad permissions and monitoring for remote C2 infrastructure.

more →  ·  More from Akamai Technologies →