Skip to content

Commit ca4dd12

Browse files
chore: update feeds 2026-04-24
1 parent 20c97f8 commit ca4dd12

18 files changed

Lines changed: 20208 additions & 20039 deletions

browser_extensions_list.csv

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
browser_extension,browser_extension_id_wildcard,browser_extension_id,metadata_category,metadata_type,metadata_link,metadata_comment,crx_file_sha256
2+
Sinceerly,*lhokehflammomchbkmpohfeidffnlpmo*,lhokehflammomchbkmpohfeidffnlpmo,malware,malicious,https://x.com/nix_eth/status/2047407665211728181,stealing api key and email text messages,
23
NexShield Advanced Web Guardian,*cpcdkmjddocikjdkbbeiaafnpdbdafmi*,cpcdkmjddocikjdkbbeiaafnpdbdafmi,malware,malicious,https://github.com/mthcht/ThreatIntel-Reports/blob/f1ceede743e0791ea9f2af7988ab9fcfd4a38d56/Intel%20Reports/thehackernews_com/2026_01_crashfix-chrome-extension-delivers_html/content.txt#L696,,c46af9ae6ab0e7567573dbc950a8ffbe30ea848fac90cd15860045fe7640199c
34
Context Extension,*omddlmnhcofjbnbflmjginpjjblphbgk*,omddlmnhcofjbnbflmjginpjjblphbgk,malware,malicious,https://x.com/i/status/2045960143209152981,Linked in public reporting to the Vercel third-party AI tool incident and a now-removed extension - Hunt with related OAuth IOC 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com,
45
OpenClaw Browser Relay,*nglingapjinhecnfejdcpihlpneeadjp*,nglingapjinhecnfejdcpihlpneeadjp,malware,malicious,https://chromewebstore.google.com/detail/openclaw-browser-relay/nglingapjinhecnfejdcpihlpneeadjp,Browser-control relay extension with local WebSocket/CDP automation - third-party depreciated package for openclaw. Added for enterprise blocklist - not as confirmed malware,133df5ad1bd5f3c5444fc6bf15040b34372dd309d7481be708ae6445c3a20c6f

feeds/elastic_detection_rule.ndjson

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

feeds/elastic_threat_intel.ndjson

Lines changed: 1881 additions & 1880 deletions
Large diffs are not rendered by default.

feeds/extsentry_feed.json

Lines changed: 14 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
{
22
"feed_name": "ExtSentry - Browser Extension Threat Intelligence",
33
"feed_version": "1.0",
4-
"generated": "2026-04-24T10:11:16Z",
4+
"generated": "2026-04-24T11:43:56Z",
55
"source": "https://github.com/mthcht/awesome-lists",
66
"license": "TLP:CLEAR",
7-
"total_indicators": 1880,
7+
"total_indicators": 1881,
88
"categories": {
9-
"malware": 1670,
9+
"malware": 1671,
1010
"PUP": 5,
1111
"compromised": 92,
1212
"cryptocurrency": 90,
@@ -18,6 +18,17 @@
1818
"PROXY/VPN": 5
1919
},
2020
"indicators": [
21+
{
22+
"extension_id": "lhokehflammomchbkmpohfeidffnlpmo",
23+
"extension_name": "Sinceerly",
24+
"wildcard_pattern": "*lhokehflammomchbkmpohfeidffnlpmo*",
25+
"category": "malware",
26+
"threat_type": "malicious",
27+
"reference_url": "https://x.com/nix_eth/status/2047407665211728181",
28+
"description": "stealing api key and email text messages",
29+
"crx_sha256": null,
30+
"chrome_webstore_url": "https://chromewebstore.google.com/detail/lhokehflammomchbkmpohfeidffnlpmo"
31+
},
2132
{
2233
"extension_id": "cpcdkmjddocikjdkbbeiaafnpdbdafmi",
2334
"extension_name": "NexShield Advanced Web Guardian",

feeds/extsentry_ioc_feed.csv

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
extension_id,extension_name,wildcard_pattern,category,threat_type,reference_url,description,chrome_webstore_url,severity,crx_sha256,first_seen,feed_source
2+
lhokehflammomchbkmpohfeidffnlpmo,Sinceerly,*lhokehflammomchbkmpohfeidffnlpmo*,malware,malicious,https://x.com/nix_eth/status/2047407665211728181,stealing api key and email text messages,https://chromewebstore.google.com/detail/lhokehflammomchbkmpohfeidffnlpmo,critical,,2026-04-24,ExtSentry (github.com/mthcht/awesome-lists)
23
cpcdkmjddocikjdkbbeiaafnpdbdafmi,NexShield Advanced Web Guardian,*cpcdkmjddocikjdkbbeiaafnpdbdafmi*,malware,malicious,https://github.com/mthcht/ThreatIntel-Reports/blob/f1ceede743e0791ea9f2af7988ab9fcfd4a38d56/Intel%20Reports/thehackernews_com/2026_01_crashfix-chrome-extension-delivers_html/content.txt#L696,,https://chromewebstore.google.com/detail/cpcdkmjddocikjdkbbeiaafnpdbdafmi,critical,c46af9ae6ab0e7567573dbc950a8ffbe30ea848fac90cd15860045fe7640199c,2026-04-24,ExtSentry (github.com/mthcht/awesome-lists)
34
omddlmnhcofjbnbflmjginpjjblphbgk,Context Extension,*omddlmnhcofjbnbflmjginpjjblphbgk*,malware,malicious,https://x.com/i/status/2045960143209152981,Linked in public reporting to the Vercel third-party AI tool incident and a now-removed extension - Hunt with related OAuth IOC 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com,https://chromewebstore.google.com/detail/omddlmnhcofjbnbflmjginpjjblphbgk,critical,,2026-04-24,ExtSentry (github.com/mthcht/awesome-lists)
45
nglingapjinhecnfejdcpihlpneeadjp,OpenClaw Browser Relay,*nglingapjinhecnfejdcpihlpneeadjp*,malware,malicious,https://chromewebstore.google.com/detail/openclaw-browser-relay/nglingapjinhecnfejdcpihlpneeadjp,Browser-control relay extension with local WebSocket/CDP automation - third-party depreciated package for openclaw. Added for enterprise blocklist - not as confirmed malware,https://chromewebstore.google.com/detail/nglingapjinhecnfejdcpihlpneeadjp,critical,133df5ad1bd5f3c5444fc6bf15040b34372dd309d7481be708ae6445c3a20c6f,2026-04-24,ExtSentry (github.com/mthcht/awesome-lists)

feeds/ioc_all_extension_ids.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
lhokehflammomchbkmpohfeidffnlpmo
12
cpcdkmjddocikjdkbbeiaafnpdbdafmi
23
omddlmnhcofjbnbflmjginpjjblphbgk
34
nglingapjinhecnfejdcpihlpneeadjp

feeds/ioc_malicious_extension_ids.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
lhokehflammomchbkmpohfeidffnlpmo
12
cpcdkmjddocikjdkbbeiaafnpdbdafmi
23
omddlmnhcofjbnbflmjginpjjblphbgk
34
nglingapjinhecnfejdcpihlpneeadjp

feeds/misp_event.json

Lines changed: 63 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"analysis": "2",
66
"distribution": "3",
77
"date": "2026-04-24",
8-
"timestamp": "1777025477",
8+
"timestamp": "1777031037",
99
"published": false,
1010
"uuid": "41ef2090-fab5-547e-9eb6-2aa8f195c66f",
1111
"Orgc": {
@@ -27,6 +27,23 @@
2727
}
2828
],
2929
"Attribute": [
30+
{
31+
"uuid": "6106685a-9ac1-5a0d-ad9a-d82a1141d895",
32+
"type": "text",
33+
"category": "Other",
34+
"to_ids": false,
35+
"value": "lhokehflammomchbkmpohfeidffnlpmo",
36+
"comment": "Sinceerly | Category: malware | Type: malicious | stealing api key and email text messages",
37+
"distribution": "5",
38+
"Tag": [
39+
{
40+
"name": "extsentry:category=\"malware\""
41+
},
42+
{
43+
"name": "extsentry:type=\"malicious\""
44+
}
45+
]
46+
},
3047
{
3148
"uuid": "9b054d03-2042-5067-adcf-94138479a22b",
3249
"type": "text",
@@ -32142,6 +32159,51 @@
3214232159
}
3214332160
],
3214432161
"Object": [
32162+
{
32163+
"uuid": "34134e2c-b22a-5ea7-a73f-c25a9c6f1653",
32164+
"name": "annotation",
32165+
"meta-category": "misc",
32166+
"description": "Suspicious/Malicious browser extension: Sinceerly",
32167+
"template_uuid": "e434b304-a905-53fb-b7df-1d552e338795",
32168+
"template_version": "1",
32169+
"Attribute": [
32170+
{
32171+
"object_relation": "text",
32172+
"type": "text",
32173+
"value": "lhokehflammomchbkmpohfeidffnlpmo",
32174+
"comment": "Browser Extension ID",
32175+
"to_ids": false
32176+
},
32177+
{
32178+
"object_relation": "text",
32179+
"type": "text",
32180+
"value": "Sinceerly",
32181+
"comment": "Extension Name",
32182+
"to_ids": false
32183+
},
32184+
{
32185+
"object_relation": "text",
32186+
"type": "text",
32187+
"value": "malware",
32188+
"comment": "Threat Category",
32189+
"to_ids": false
32190+
},
32191+
{
32192+
"object_relation": "text",
32193+
"type": "text",
32194+
"value": "malicious",
32195+
"comment": "Threat Type",
32196+
"to_ids": false
32197+
},
32198+
{
32199+
"object_relation": "text",
32200+
"type": "link",
32201+
"value": "https://x.com/nix_eth/status/2047407665211728181",
32202+
"comment": "Reference URL",
32203+
"to_ids": false
32204+
}
32205+
]
32206+
},
3214532207
{
3214632208
"uuid": "a2e1d604-807c-521d-9501-f2e9f0688990",
3214732209
"name": "annotation",

feeds/misp_warninglist.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@
99
"other"
1010
],
1111
"list": [
12+
"lhokehflammomchbkmpohfeidffnlpmo",
1213
"cpcdkmjddocikjdkbbeiaafnpdbdafmi",
1314
"omddlmnhcofjbnbflmjginpjjblphbgk",
1415
"nglingapjinhecnfejdcpihlpneeadjp",

0 commit comments

Comments
 (0)