Security News Malicious Chrome extensions can spoof password managers in new attack

Jonny Quest

Level 23
Thread author
Verified
Top Poster
Well-known
Mar 2, 2023
1,247
This is the part that caught my eye.

In SquareX's demonstration, the attackers impersonate the 1Password password manager extension by first disabling the legitimate one using the 'chrome.management' API, or if the permissions aren't available, user interface manipulation tactics to hide it from the user.

Simultaneously, the malicious extension switches its icon to mimic that of 1Password, changes its name accordingly, and displays a fake login popup that matches the appearance of the real one.

To force the user into entering their credentials, when attempting to log in to a site, a fake "Session Expired" prompt is served, making the victim think they were logged out.

This will prompt the user to log back into 1Password through a phishing form that sends inputted credentials back to the attackers.
1password.jpg
 

Jonny Quest

Level 23
Thread author
Verified
Top Poster
Well-known
Mar 2, 2023
1,247
Last edited:

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
7,900
@oldschool I thought about you and your post when I saw this article on Bleeping Computer.

This article highlights how the 'chrome.management' API is ripe for the pickings. I personally rely mainly on my little black book for password management, especially critical ones.

And it goes without saying that users should ...
Only use a minimal amount of trusted extensions
(y)(y)
 

Jonny Quest

Level 23
Thread author
Verified
Top Poster
Well-known
Mar 2, 2023
1,247
Does this affect a password manager with a local database only?
It doesn't sound like it, like with KeePass? That's what I was thinking, that if I were truly concerned, I could uninstall the Proton Pass extensions and just work from the desktop app (in my case) and copy and paste from there. Probably like you could also do with the Bitwarden desktop app.

But would there be a security risk in my doing it that way, as far as what may be stored in Clipboard, or in the browser somewhere, compared to just typing things in?
 
Last edited:

rashmi

Level 16
Jan 15, 2024
766
It doesn't sound like it, like with KeePass? That's what I was thinking, that if I were truly concerned, I could uninstall the Proton Pass extensions and just work from the desktop app (in my case) and copy and paste from there. Probably like you could also do with the Bitwarden desktop app.

But would there be a security risk in my doing it that way, as far as what may be stored in Clipboard, or in the browser somewhere, compared to just typing things in?
I meant a password manager with a local database and an extension, but no cloud database. I use Enpass password manager, which has no cloud database. If I'm correct, some password managers have a different password for the cloud database. I guess it would help in this scenario.
 

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
7,900

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top