Security researchers have identified five malicious Chrome extensions that impersonate popular human resource (HR) and enterprise resource planning (ERP) platforms, such as Workday and NetSuite. These extensions were designed to facilitate credential theft and session hijacking, posing significant risks to users and organizations.
According to research conducted by Socket, the extensions enabled attackers to steal authentication tokens, block incident response capabilities, and potentially take over user accounts. The plugins, which mimicked legitimate software, were removed from the Google Chrome Web Store shortly after their discovery, but users who had installed them remain vulnerable until they uninstall the extensions and conduct thorough security scans.
The malicious extensions, which include names like DataByCloud Access Tool and DataByCloud 1, were collectively downloaded 2,739 times. While this number suggests limited effectiveness, the implications of a full account takeover in organizations using these platforms can be severe. Medium to large enterprises rely on systems such as Workday, NetSuite, and SuccessFactors for crucial functions like HR, finance, payroll, and operations. A successful attack could result in extensive damage, affecting thousands of individuals and potentially costing millions of dollars.
Despite their removal from the Chrome Web Store, reports indicate that some of these malicious extensions may still be available on third-party download sites, including Softonic. At the time of this report, the Softonic website appeared to be offline, preventing independent verification of these claims.
Socket further pointed out that some of the extensions had been published for over four years, highlighting a concerning trend in the persistence of such threats. “The combination of continuous credential theft, administrative interface blocking, and session hijacking creates a scenario where security teams can detect unauthorized access but cannot remediate through normal channels,” the researchers noted.
Organizations using these HR and ERP systems should remain vigilant, scrutinizing any installed browser extensions. It is essential to maintain robust cybersecurity practices to mitigate the risks associated with malicious software and safeguard sensitive information.


































