Malicious Extensions Now Cross Into Native Code

A browser extension is no longer contained just because it runs in the browser. If it can talk to a trusted local helper, the compromise can jump out of the sandbox and land on the desktop as native malware. Zscaler says the Edgecution campaign used a malicious Microsoft Edge extension, Teams-based social engineering, and Chrome Native Messaging to hand commands to a local Python backdoor. The activity is tied to ransomware-related intrusions and an initial access broker linked to Payouts Kings, with the extension running in headless Edge and feeding results back to the operator. The practical boundary has moved from browser permissions to the trust link between the extension and the native host. Teams support impersonation gets the extension installed, but the real risk is that extension-to-desktop communication can turn a browser foothold into endpoint malware delivery.

Part of the PlainSec briefing for 2026-06-25

Sources