Skip to content

Commit ae1bd2d

Browse files
chore: update feeds 2026-04-19
1 parent 5289b1f commit ae1bd2d

19 files changed

Lines changed: 20242 additions & 20040 deletions

browser_extensions_list.csv

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
1-
browser_extension,browser_extension_id_wildcard,browser_extension_id,metadata_category,metadata_type,metadata_link,metadata_comment,crx_file_sha256
1+
browser_extension,browser_extension_id_wildcard,browser_extension_id,metadata_category,metadata_type,metadata_link,metadata_comment,crx_file_sha256
2+
OpenClaw Browser Relay,*nglingapjinhecnfejdcpihlpneeadjp*,nglingapjinhecnfejdcpihlpneeadjp,malware,malicious,https://chromewebstore.google.com/detail/openclaw-browser-relay/nglingapjinhecnfejdcpihlpneeadjp,Browser-control relay extension with local WebSocket/CDP automation - third-party depreciated package for openclaw. Added for enterprise blocklist - not as confirmed malware,133df5ad1bd5f3c5444fc6bf15040b34372dd309d7481be708ae6445c3a20c6f
23
Telegram Multi-account,*obifanppcpchlehkjipahhphbcbjekfa*,obifanppcpchlehkjipahhphbcbjekfa,malware,malicious,https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2,,
34
Web Client for Telegram - Teleside,*mdcfennpfgkngnibjbpnpaafcjnhcjno*,mdcfennpfgkngnibjbpnpaafcjnhcjno,malware,malicious,https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2,,
45
YouSide - Youtube Sidebar,*mmecpiobcdbjkaijljohghhpfgngpjmk*,mmecpiobcdbjkaijljohghhpfgngpjmk,malware,malicious,https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2,,

feeds/elastic_detection_rule.ndjson

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

feeds/elastic_threat_intel.ndjson

Lines changed: 1881 additions & 1880 deletions
Large diffs are not rendered by default.

feeds/extsentry_feed.json

Lines changed: 14 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
{
22
"feed_name": "ExtSentry - Browser Extension Threat Intelligence",
33
"feed_version": "1.0",
4-
"generated": "2026-04-19T06:01:04Z",
4+
"generated": "2026-04-19T07:23:01Z",
55
"source": "https://github.com/mthcht/awesome-lists",
66
"license": "TLP:CLEAR",
7-
"total_indicators": 1880,
7+
"total_indicators": 1881,
88
"categories": {
9-
"malware": 1670,
9+
"malware": 1671,
1010
"PUP": 5,
1111
"compromised": 92,
1212
"cryptocurrency": 90,
@@ -18,6 +18,17 @@
1818
"PROXY/VPN": 5
1919
},
2020
"indicators": [
21+
{
22+
"extension_id": "nglingapjinhecnfejdcpihlpneeadjp",
23+
"extension_name": "OpenClaw Browser Relay",
24+
"wildcard_pattern": "*nglingapjinhecnfejdcpihlpneeadjp*",
25+
"category": "malware",
26+
"threat_type": "malicious",
27+
"reference_url": "https://chromewebstore.google.com/detail/openclaw-browser-relay/nglingapjinhecnfejdcpihlpneeadjp",
28+
"description": "Browser-control relay extension with local WebSocket/CDP automation - third-party depreciated package for openclaw. Added for enterprise blocklist - not as confirmed malware",
29+
"crx_sha256": "133df5ad1bd5f3c5444fc6bf15040b34372dd309d7481be708ae6445c3a20c6f",
30+
"chrome_webstore_url": "https://chromewebstore.google.com/detail/nglingapjinhecnfejdcpihlpneeadjp"
31+
},
2132
{
2233
"extension_id": "obifanppcpchlehkjipahhphbcbjekfa",
2334
"extension_name": "Telegram Multi-account",

feeds/extsentry_ioc_feed.csv

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
extension_id,extension_name,wildcard_pattern,category,threat_type,reference_url,description,chrome_webstore_url,severity,crx_sha256,first_seen,feed_source
2+
nglingapjinhecnfejdcpihlpneeadjp,OpenClaw Browser Relay,*nglingapjinhecnfejdcpihlpneeadjp*,malware,malicious,https://chromewebstore.google.com/detail/openclaw-browser-relay/nglingapjinhecnfejdcpihlpneeadjp,Browser-control relay extension with local WebSocket/CDP automation - third-party depreciated package for openclaw. Added for enterprise blocklist - not as confirmed malware,https://chromewebstore.google.com/detail/nglingapjinhecnfejdcpihlpneeadjp,critical,133df5ad1bd5f3c5444fc6bf15040b34372dd309d7481be708ae6445c3a20c6f,2026-04-19,ExtSentry (github.com/mthcht/awesome-lists)
23
obifanppcpchlehkjipahhphbcbjekfa,Telegram Multi-account,*obifanppcpchlehkjipahhphbcbjekfa*,malware,malicious,https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2,,https://chromewebstore.google.com/detail/obifanppcpchlehkjipahhphbcbjekfa,critical,,2026-04-19,ExtSentry (github.com/mthcht/awesome-lists)
34
mdcfennpfgkngnibjbpnpaafcjnhcjno,Web Client for Telegram - Teleside,*mdcfennpfgkngnibjbpnpaafcjnhcjno*,malware,malicious,https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2,,https://chromewebstore.google.com/detail/mdcfennpfgkngnibjbpnpaafcjnhcjno,critical,,2026-04-19,ExtSentry (github.com/mthcht/awesome-lists)
45
mmecpiobcdbjkaijljohghhpfgngpjmk,YouSide - Youtube Sidebar,*mmecpiobcdbjkaijljohghhpfgngpjmk*,malware,malicious,https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2,,https://chromewebstore.google.com/detail/mmecpiobcdbjkaijljohghhpfgngpjmk,critical,,2026-04-19,ExtSentry (github.com/mthcht/awesome-lists)

feeds/ioc_all_extension_ids.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
nglingapjinhecnfejdcpihlpneeadjp
12
obifanppcpchlehkjipahhphbcbjekfa
23
mdcfennpfgkngnibjbpnpaafcjnhcjno
34
mmecpiobcdbjkaijljohghhpfgngpjmk

feeds/ioc_crx_sha256_hashes.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
133df5ad1bd5f3c5444fc6bf15040b34372dd309d7481be708ae6445c3a20c6f
12
0cbf101e96f6d5c4146812f07105f8b89bd76dd994f540470cd1c4bc37df37d5
23
21dd863ff9bbd15da01c1218bf92bd65eeae04a41876e10c41733b58035414c4
34
9d0f550ac883455ed64da402cdb0c822c90de405c540678e0697b77fe20de3cf

feeds/ioc_malicious_extension_ids.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
nglingapjinhecnfejdcpihlpneeadjp
12
obifanppcpchlehkjipahhphbcbjekfa
23
mdcfennpfgkngnibjbpnpaafcjnhcjno
34
mmecpiobcdbjkaijljohghhpfgngpjmk

feeds/misp_event.json

Lines changed: 87 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"analysis": "2",
66
"distribution": "3",
77
"date": "2026-04-19",
8-
"timestamp": "1776578465",
8+
"timestamp": "1776583381",
99
"published": false,
1010
"uuid": "41ef2090-fab5-547e-9eb6-2aa8f195c66f",
1111
"Orgc": {
@@ -27,6 +27,40 @@
2727
}
2828
],
2929
"Attribute": [
30+
{
31+
"uuid": "70c24c8a-98cf-5284-ad5b-fa87d91fd5a7",
32+
"type": "text",
33+
"category": "Other",
34+
"to_ids": false,
35+
"value": "nglingapjinhecnfejdcpihlpneeadjp",
36+
"comment": "OpenClaw Browser Relay | Category: malware | Type: malicious | Browser-control relay extension with local WebSocket/CDP automation - third-party depreciated package for openclaw. Added for enterprise blocklist - not as confirmed malware",
37+
"distribution": "5",
38+
"Tag": [
39+
{
40+
"name": "extsentry:category=\"malware\""
41+
},
42+
{
43+
"name": "extsentry:type=\"malicious\""
44+
}
45+
]
46+
},
47+
{
48+
"uuid": "b1b797e3-c239-5fab-acb2-81729019cbff",
49+
"type": "sha256",
50+
"category": "Payload delivery",
51+
"to_ids": true,
52+
"value": "133df5ad1bd5f3c5444fc6bf15040b34372dd309d7481be708ae6445c3a20c6f",
53+
"comment": "CRX file hash for OpenClaw Browser Relay (nglingapjinhecnfejdcpihlpneeadjp)",
54+
"distribution": "5",
55+
"Tag": [
56+
{
57+
"name": "extsentry:category=\"malware\""
58+
},
59+
{
60+
"name": "extsentry:type=\"malicious\""
61+
}
62+
]
63+
},
3064
{
3165
"uuid": "29bf0cc7-d0c4-590a-aa90-17e47e6ff02d",
3266
"type": "text",
@@ -32108,6 +32142,58 @@
3210832142
}
3210932143
],
3211032144
"Object": [
32145+
{
32146+
"uuid": "daf46dee-21fe-5199-b2d4-cf680a33455f",
32147+
"name": "annotation",
32148+
"meta-category": "misc",
32149+
"description": "Suspicious/Malicious browser extension: OpenClaw Browser Relay",
32150+
"template_uuid": "e434b304-a905-53fb-b7df-1d552e338795",
32151+
"template_version": "1",
32152+
"Attribute": [
32153+
{
32154+
"object_relation": "text",
32155+
"type": "text",
32156+
"value": "nglingapjinhecnfejdcpihlpneeadjp",
32157+
"comment": "Browser Extension ID",
32158+
"to_ids": false
32159+
},
32160+
{
32161+
"object_relation": "text",
32162+
"type": "text",
32163+
"value": "OpenClaw Browser Relay",
32164+
"comment": "Extension Name",
32165+
"to_ids": false
32166+
},
32167+
{
32168+
"object_relation": "text",
32169+
"type": "text",
32170+
"value": "malware",
32171+
"comment": "Threat Category",
32172+
"to_ids": false
32173+
},
32174+
{
32175+
"object_relation": "text",
32176+
"type": "text",
32177+
"value": "malicious",
32178+
"comment": "Threat Type",
32179+
"to_ids": false
32180+
},
32181+
{
32182+
"object_relation": "text",
32183+
"type": "sha256",
32184+
"value": "133df5ad1bd5f3c5444fc6bf15040b34372dd309d7481be708ae6445c3a20c6f",
32185+
"comment": "CRX File SHA-256",
32186+
"to_ids": true
32187+
},
32188+
{
32189+
"object_relation": "text",
32190+
"type": "link",
32191+
"value": "https://chromewebstore.google.com/detail/openclaw-browser-relay/nglingapjinhecnfejdcpihlpneeadjp",
32192+
"comment": "Reference URL",
32193+
"to_ids": false
32194+
}
32195+
]
32196+
},
3211132197
{
3211232198
"uuid": "f089e386-fca0-5989-9c52-16c036681cbb",
3211332199
"name": "annotation",

feeds/misp_warninglist.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@
99
"other"
1010
],
1111
"list": [
12+
"nglingapjinhecnfejdcpihlpneeadjp",
1213
"obifanppcpchlehkjipahhphbcbjekfa",
1314
"mdcfennpfgkngnibjbpnpaafcjnhcjno",
1415
"mmecpiobcdbjkaijljohghhpfgngpjmk",

0 commit comments

Comments
 (0)