StegoAd malicious Edge extension operation
Malware Activity
Summary
Hide ▲
Show ▼
The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs that reached up to 2.6 million users. The extensions stayed dormant for days, evaded analysis checks, and expanded into session hijacking and covert telemetry.
Related Happenings
ModHeader browser extension hidden browsing-history collector
Malware Activity
H score42
First: 13.07.2026 20:17
Last: 13.07.2026 20:17
Sources 1
About this happening:
The ModHeader browser extension shipped a hidden browsing-history collector in its official store version, exposing about 1.6 million installs to covert domain and...
ModHeader browser extension hidden browsing-history collector
Malware ActivityAbout this happening: The ModHeader browser extension shipped a hidden browsing-history collector in its official store version, exposing about 1.6 million installs to covert domain and...
Search for perplexity ai malicious Chrome extension
Malware Activity
H score29
First: 29.06.2026 21:40
Last: 29.06.2026 21:40
Sources 1
About this happening:
A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
Search for perplexity ai malicious Chrome extension
Malware ActivityAbout this happening: A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
SHub Reaper macOS infostealer variant
Malware Activity
H score23
First: 19.05.2026 00:42
Last: 19.05.2026 00:42
Sources 1
About this happening:
The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
SHub Reaper macOS infostealer variant
Malware ActivityAbout this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
GlassWorm OpenVSX sleeper extension campaign
Campaign
H score45
First: 28.04.2026 00:41
Last: 28.04.2026 00:41
Sources 1
About this happening:
The GlassWorm operation has launched a new wave against OpenVSX, seeding 73 sleeper extensions that become malicious after an update and can deliver malware to...
GlassWorm OpenVSX sleeper extension campaign
CampaignAbout this happening: The GlassWorm operation has launched a new wave against OpenVSX, seeding 73 sleeper extensions that become malicious after an update and can deliver malware to...
Timeline
-
29.06.2026 11:32 2 articles · 16d ago
Microsoft removes 119 malicious Edge extensions
Mitigation Patch UpdateMicrosoft shut down 119 Edge Add-ons extensions linked to StegoAd and suspended the 90-plus developer accounts behind them after the extensions hid payloads in image and font files, stayed dormant through evasion checks, and later stole credentials and ran ad fraud. Microsoft also told users to compare installed add-ons against the removal list, change passwords for sensitive accounts, review recent sign-in activity, and enable strong two-factor authentication.
Show sources
- Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts — thehackernews.com — 29.06.2026 11:32
- Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts — thehackernews.com — 29.06.2026 11:32
-
29.06.2026 11:32 1 articles · 16d ago
Microsoft details StegoAd credential theft and ad fraud tactics
Technical Analysis UpdateMicrosoft described StegoAd as a long-running malicious extension operation active since at least 2021, with 119 extensions that hid code in PNG, WebP, and WOFF2 files, used delayed activation and server-side validation, and in some variants fetched payloads from command-and-control servers. The retrieved payloads stole Google credentials and second-factor codes, harvested WordPress admin logins, exfiltrated cookies for session hijacking, and drove ad fraud through injected ads, affiliate hijacking, and redirected searches.
Show sources
- Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts — thehackernews.com — 29.06.2026 11:32