Security · 1h ago
Malicious Edge extension uses Native Messaging to deploy backdoor
A malicious Edge extension named 'Edgecution' was used in a ransomware attack to escape the browser sandbox via Native Messaging. It deployed a Python-based backdoor on the victim's system. The attack highlights a novel technique for bypassing browser security measures.
Meridian48 take
While not widespread, this attack shows that browser extensions remain a potent vector for malware, especially when abusing legitimate APIs like Native Messaging.
Read the full reporting
Malicious Edge extension abuses Native Messaging as bridge to malware →
Bleeping Computer
edge-extensionnative-messaging