Skip to content

Commit ccfa535

Browse files
chore: update feeds 2026-04-20
1 parent 5067b28 commit ccfa535

18 files changed

Lines changed: 19806 additions & 20313 deletions

browser_extensions_list.csv

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -110,10 +110,8 @@ Swimming Pro,*phfkdailnomcbcknpdmokejhellbecjb*,phfkdailnomcbcknpdmokejhellbecjb
110110
InterAlt,*pkghgkfjhjghinikeanecbgjehojfhdg*,pkghgkfjhjghinikeanecbgjehojfhdg,malware,malicious,https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2,,
111111
Gold of Egypt - Slot Machine,*pllkanemicadpcmkfodglahcocfdgkhj*,pllkanemicadpcmkfodglahcocfdgkhj,malware,malicious,https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2,,
112112
Pro search,*jnannpdmmiphnkpaooplhegabbghlplj*,jnannpdmmiphnkpaooplhegabbghlplj,malware,malicious,,shows fake antivirus alerts constantly and capture browsing activities,
113-
ChatGPT Ad Blocker,*ipmmidjikiklckbngllogmggoofbhjikgb*,ipmmidjikiklckbngllogmggoofbhjikgb,malware,malicious,https://github.com/mthcht/ThreatIntel-Reports/blob/b65e17489a8485bf5893c481de58e363c2ce35f6/Intel%20Reports/thehackernews_com/2026_04_weekly-recap-axios-hack-chrome-0-day_html/content.txt#L788,steal the ChatGPT conversations data,
114113
Color Picker - Eyedropper,*gogbiohkminacikoppmljeolgccpmlop*,gogbiohkminacikoppmljeolgccpmlop,PUP,privacy,https://x.com/tuckner/status/2039777577452155131,spying on you,
115114
JSON Formatter,*bcjindcccaagfpapjjmafapmmgkkhgoa*,bcjindcccaagfpapjjmafapmmgkkhgoa,PUP,privacy,https://chromewebstore.google.com/detail/json-formatter/bcjindcccaagfpapjjmafapmmgkkhgoa/reviews,https://x.com/wesbos/status/2039355472830939319?s=20,
116-
,*nplfchpahihleeejpjmodggckakhglee*,plfchpahihleeejpjmodggckakhglee,malware,malicious,https://x.com/i/status/1907925793336078675,bank credential stealer,
117115
,*ckkjdiimhlanonhceggkfjlmjnenpmfm*,ckkjdiimhlanonhceggkfjlmjnenpmfm,malware,malicious,https://x.com/i/status/1907925793336078675,bank credential stealer,
118116
Chrome MCP Server - AI Browser Control,*fpeabamapgecnidibdmjoepaiehokgda*,fpeabamapgecnidibdmjoepaiehokgda,malware,malicious,https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/dbdcea6a9f5684a9268c39e60c667c5c9c06263b/2026-02-11-IOCs-for-RAT-disguinsed-as-AI-based-browser-extension.txt,RAT AI browser extension,0cbf101e96f6d5c4146812f07105f8b89bd76dd994f540470cd1c4bc37df37d5
119117
OmniBar AI Chat and Search,*ajfanjhcdgaohcbphpaceglgpgaaohod*,ajfanjhcdgaohcbphpaceglgpgaaohod,malware,malicious,https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-03-09-Threat-Alert-30K-domains-distributing-malicious-AI-related-browser-extension.txt,Malicious AI browser extension,21dd863ff9bbd15da01c1218bf92bd65eeae04a41876e10c41733b58035414c4
@@ -1789,7 +1787,6 @@ FakeGPT,*hacfaophiklaeolhnmckojjjjbnappen*,hacfaophiklaeolhnmckojjjjbnappen,malw
17891787
,*olkcbimhgpenhcboejacjpmohcincfdb*,olkcbimhgpenhcboejacjpmohcincfdb,malware,malicious,https://blog.avast.com/malicious-extensions-chrome-web-store,,
17901788
,*ooaehdahoiljphlijlaplnbeaeeimhbb*,ooaehdahoiljphlijlaplnbeaeeimhbb,malware,malicious,https://blog.avast.com/malicious-extensions-chrome-web-store,,
17911789
,*pidecdgcabcolloikegacdjejomeodji*,pidecdgcabcolloikegacdjejomeodji,malware,malicious,https://blog.avast.com/malicious-extensions-chrome-web-store,,
1792-
,*nmmhkkegccagdldgiimedpiccmgmiedagg4*,nmmhkkegccagdldgiimedpiccmgmiedagg4,malware,malicious,https://www.malwarebytes.com/blog/threat-intelligence/2023/07/criminals-target-businesses-with-malicious-extension-for-metas-ads-manager-and-accidentally-leak-stolen-accounts,,
17931790
,*dlddmedljhmbgdhapibnagaanenmajcm*,dlddmedljhmbgdhapibnagaanenmajcm,malware,malicious,https://www.welivesecurity.com/2013/07/30/versatile-and-infectious-win64expiro-is-a-cross-platform-file-infector/,,
17941791
Micro Search Chrome Extension,*bbgbmlkfflffccognkcbbmkakbejnado*,bbgbmlkfflffccognkcbbmkakbejnado,malware,malicious,https://keepaware.com/blog/trojan-extension-malware-3-year-campaign-300k-infections,,
17951792
Qcom search bar,*bcmmbhidjmodkbeidljmhcijhkchokcj*,bcmmbhidjmodkbeidljmhcijhkchokcj,malware,malicious,https://keepaware.com/blog/trojan-extension-malware-3-year-campaign-300k-infections,,

feeds/elastic_detection_rule.ndjson

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

feeds/elastic_threat_intel.ndjson

Lines changed: 1879 additions & 1882 deletions
Large diffs are not rendered by default.

feeds/extsentry_feed.json

Lines changed: 3 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
{
22
"feed_name": "ExtSentry - Browser Extension Threat Intelligence",
33
"feed_version": "1.0",
4-
"generated": "2026-04-20T09:27:54Z",
4+
"generated": "2026-04-20T10:36:16Z",
55
"source": "https://github.com/mthcht/awesome-lists",
66
"license": "TLP:CLEAR",
7-
"total_indicators": 1882,
7+
"total_indicators": 1879,
88
"categories": {
9-
"malware": 1672,
9+
"malware": 1669,
1010
"PUP": 5,
1111
"compromised": 92,
1212
"cryptocurrency": 90,
@@ -1239,17 +1239,6 @@
12391239
"crx_sha256": null,
12401240
"chrome_webstore_url": "https://chromewebstore.google.com/detail/jnannpdmmiphnkpaooplhegabbghlplj"
12411241
},
1242-
{
1243-
"extension_id": "ipmmidjikiklckbngllogmggoofbhjikgb",
1244-
"extension_name": "ChatGPT Ad Blocker",
1245-
"wildcard_pattern": "*ipmmidjikiklckbngllogmggoofbhjikgb*",
1246-
"category": "malware",
1247-
"threat_type": "malicious",
1248-
"reference_url": "https://github.com/mthcht/ThreatIntel-Reports/blob/b65e17489a8485bf5893c481de58e363c2ce35f6/Intel%20Reports/thehackernews_com/2026_04_weekly-recap-axios-hack-chrome-0-day_html/content.txt#L788",
1249-
"description": "steal the ChatGPT conversations data",
1250-
"crx_sha256": null,
1251-
"chrome_webstore_url": "https://chromewebstore.google.com/detail/ipmmidjikiklckbngllogmggoofbhjikgb"
1252-
},
12531242
{
12541243
"extension_id": "gogbiohkminacikoppmljeolgccpmlop",
12551244
"extension_name": "Color Picker - Eyedropper",
@@ -1272,17 +1261,6 @@
12721261
"crx_sha256": null,
12731262
"chrome_webstore_url": "https://chromewebstore.google.com/detail/bcjindcccaagfpapjjmafapmmgkkhgoa"
12741263
},
1275-
{
1276-
"extension_id": "plfchpahihleeejpjmodggckakhglee",
1277-
"extension_name": null,
1278-
"wildcard_pattern": "*nplfchpahihleeejpjmodggckakhglee*",
1279-
"category": "malware",
1280-
"threat_type": "malicious",
1281-
"reference_url": "https://x.com/i/status/1907925793336078675",
1282-
"description": "bank credential stealer",
1283-
"crx_sha256": null,
1284-
"chrome_webstore_url": "https://chromewebstore.google.com/detail/plfchpahihleeejpjmodggckakhglee"
1285-
},
12861264
{
12871265
"extension_id": "ckkjdiimhlanonhceggkfjlmjnenpmfm",
12881266
"extension_name": null,
@@ -19708,17 +19686,6 @@
1970819686
"crx_sha256": null,
1970919687
"chrome_webstore_url": "https://chromewebstore.google.com/detail/pidecdgcabcolloikegacdjejomeodji"
1971019688
},
19711-
{
19712-
"extension_id": "nmmhkkegccagdldgiimedpiccmgmiedagg4",
19713-
"extension_name": null,
19714-
"wildcard_pattern": "*nmmhkkegccagdldgiimedpiccmgmiedagg4*",
19715-
"category": "malware",
19716-
"threat_type": "malicious",
19717-
"reference_url": "https://www.malwarebytes.com/blog/threat-intelligence/2023/07/criminals-target-businesses-with-malicious-extension-for-metas-ads-manager-and-accidentally-leak-stolen-accounts",
19718-
"description": "",
19719-
"crx_sha256": null,
19720-
"chrome_webstore_url": "https://chromewebstore.google.com/detail/nmmhkkegccagdldgiimedpiccmgmiedagg4"
19721-
},
1972219689
{
1972319690
"extension_id": "dlddmedljhmbgdhapibnagaanenmajcm",
1972419691
"extension_name": null,

feeds/extsentry_ioc_feed.csv

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -110,10 +110,8 @@ phfkdailnomcbcknpdmokejhellbecjb,Swimming Pro,*phfkdailnomcbcknpdmokejhellbecjb*
110110
pkghgkfjhjghinikeanecbgjehojfhdg,InterAlt,*pkghgkfjhjghinikeanecbgjehojfhdg*,malware,malicious,https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2,,https://chromewebstore.google.com/detail/pkghgkfjhjghinikeanecbgjehojfhdg,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
111111
pllkanemicadpcmkfodglahcocfdgkhj,Gold of Egypt - Slot Machine,*pllkanemicadpcmkfodglahcocfdgkhj*,malware,malicious,https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2,,https://chromewebstore.google.com/detail/pllkanemicadpcmkfodglahcocfdgkhj,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
112112
jnannpdmmiphnkpaooplhegabbghlplj,Pro search,*jnannpdmmiphnkpaooplhegabbghlplj*,malware,malicious,,shows fake antivirus alerts constantly and capture browsing activities,https://chromewebstore.google.com/detail/jnannpdmmiphnkpaooplhegabbghlplj,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
113-
ipmmidjikiklckbngllogmggoofbhjikgb,ChatGPT Ad Blocker,*ipmmidjikiklckbngllogmggoofbhjikgb*,malware,malicious,https://github.com/mthcht/ThreatIntel-Reports/blob/b65e17489a8485bf5893c481de58e363c2ce35f6/Intel%20Reports/thehackernews_com/2026_04_weekly-recap-axios-hack-chrome-0-day_html/content.txt#L788,steal the ChatGPT conversations data,https://chromewebstore.google.com/detail/ipmmidjikiklckbngllogmggoofbhjikgb,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
114113
gogbiohkminacikoppmljeolgccpmlop,Color Picker - Eyedropper,*gogbiohkminacikoppmljeolgccpmlop*,PUP,privacy,https://x.com/tuckner/status/2039777577452155131,spying on you,https://chromewebstore.google.com/detail/gogbiohkminacikoppmljeolgccpmlop,low,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
115114
bcjindcccaagfpapjjmafapmmgkkhgoa,JSON Formatter,*bcjindcccaagfpapjjmafapmmgkkhgoa*,PUP,privacy,https://chromewebstore.google.com/detail/json-formatter/bcjindcccaagfpapjjmafapmmgkkhgoa/reviews,https://x.com/wesbos/status/2039355472830939319?s=20,https://chromewebstore.google.com/detail/bcjindcccaagfpapjjmafapmmgkkhgoa,low,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
116-
plfchpahihleeejpjmodggckakhglee,bank credential stealer,*nplfchpahihleeejpjmodggckakhglee*,malware,malicious,https://x.com/i/status/1907925793336078675,bank credential stealer,https://chromewebstore.google.com/detail/plfchpahihleeejpjmodggckakhglee,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
117115
ckkjdiimhlanonhceggkfjlmjnenpmfm,bank credential stealer,*ckkjdiimhlanonhceggkfjlmjnenpmfm*,malware,malicious,https://x.com/i/status/1907925793336078675,bank credential stealer,https://chromewebstore.google.com/detail/ckkjdiimhlanonhceggkfjlmjnenpmfm,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
118116
fpeabamapgecnidibdmjoepaiehokgda,Chrome MCP Server - AI Browser Control,*fpeabamapgecnidibdmjoepaiehokgda*,malware,malicious,https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/dbdcea6a9f5684a9268c39e60c667c5c9c06263b/2026-02-11-IOCs-for-RAT-disguinsed-as-AI-based-browser-extension.txt,RAT AI browser extension,https://chromewebstore.google.com/detail/fpeabamapgecnidibdmjoepaiehokgda,critical,0cbf101e96f6d5c4146812f07105f8b89bd76dd994f540470cd1c4bc37df37d5,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
119117
ajfanjhcdgaohcbphpaceglgpgaaohod,OmniBar AI Chat and Search,*ajfanjhcdgaohcbphpaceglgpgaaohod*,malware,malicious,https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-03-09-Threat-Alert-30K-domains-distributing-malicious-AI-related-browser-extension.txt,Malicious AI browser extension,https://chromewebstore.google.com/detail/ajfanjhcdgaohcbphpaceglgpgaaohod,critical,21dd863ff9bbd15da01c1218bf92bd65eeae04a41876e10c41733b58035414c4,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
@@ -1789,7 +1787,6 @@ oejfpkocfgochpkljdlmcnibecancpnl,,*oejfpkocfgochpkljdlmcnibecancpnl*,malware,mal
17891787
olkcbimhgpenhcboejacjpmohcincfdb,,*olkcbimhgpenhcboejacjpmohcincfdb*,malware,malicious,https://blog.avast.com/malicious-extensions-chrome-web-store,,https://chromewebstore.google.com/detail/olkcbimhgpenhcboejacjpmohcincfdb,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
17901788
ooaehdahoiljphlijlaplnbeaeeimhbb,,*ooaehdahoiljphlijlaplnbeaeeimhbb*,malware,malicious,https://blog.avast.com/malicious-extensions-chrome-web-store,,https://chromewebstore.google.com/detail/ooaehdahoiljphlijlaplnbeaeeimhbb,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
17911789
pidecdgcabcolloikegacdjejomeodji,,*pidecdgcabcolloikegacdjejomeodji*,malware,malicious,https://blog.avast.com/malicious-extensions-chrome-web-store,,https://chromewebstore.google.com/detail/pidecdgcabcolloikegacdjejomeodji,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
1792-
nmmhkkegccagdldgiimedpiccmgmiedagg4,,*nmmhkkegccagdldgiimedpiccmgmiedagg4*,malware,malicious,https://www.malwarebytes.com/blog/threat-intelligence/2023/07/criminals-target-businesses-with-malicious-extension-for-metas-ads-manager-and-accidentally-leak-stolen-accounts,,https://chromewebstore.google.com/detail/nmmhkkegccagdldgiimedpiccmgmiedagg4,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
17931790
dlddmedljhmbgdhapibnagaanenmajcm,,*dlddmedljhmbgdhapibnagaanenmajcm*,malware,malicious,https://www.welivesecurity.com/2013/07/30/versatile-and-infectious-win64expiro-is-a-cross-platform-file-infector/,,https://chromewebstore.google.com/detail/dlddmedljhmbgdhapibnagaanenmajcm,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
17941791
bbgbmlkfflffccognkcbbmkakbejnado,Micro Search Chrome Extension,*bbgbmlkfflffccognkcbbmkakbejnado*,malware,malicious,https://keepaware.com/blog/trojan-extension-malware-3-year-campaign-300k-infections,,https://chromewebstore.google.com/detail/bbgbmlkfflffccognkcbbmkakbejnado,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)
17951792
bcmmbhidjmodkbeidljmhcijhkchokcj,Qcom search bar,*bcmmbhidjmodkbeidljmhcijhkchokcj*,malware,malicious,https://keepaware.com/blog/trojan-extension-malware-3-year-campaign-300k-infections,,https://chromewebstore.google.com/detail/bcmmbhidjmodkbeidljmhcijhkchokcj,critical,,2026-04-20,ExtSentry (github.com/mthcht/awesome-lists)

feeds/ioc_all_extension_ids.txt

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -109,10 +109,8 @@ phfkdailnomcbcknpdmokejhellbecjb
109109
pkghgkfjhjghinikeanecbgjehojfhdg
110110
pllkanemicadpcmkfodglahcocfdgkhj
111111
jnannpdmmiphnkpaooplhegabbghlplj
112-
ipmmidjikiklckbngllogmggoofbhjikgb
113112
gogbiohkminacikoppmljeolgccpmlop
114113
bcjindcccaagfpapjjmafapmmgkkhgoa
115-
plfchpahihleeejpjmodggckakhglee
116114
ckkjdiimhlanonhceggkfjlmjnenpmfm
117115
fpeabamapgecnidibdmjoepaiehokgda
118116
ajfanjhcdgaohcbphpaceglgpgaaohod
@@ -1788,7 +1786,6 @@ oejfpkocfgochpkljdlmcnibecancpnl
17881786
olkcbimhgpenhcboejacjpmohcincfdb
17891787
ooaehdahoiljphlijlaplnbeaeeimhbb
17901788
pidecdgcabcolloikegacdjejomeodji
1791-
nmmhkkegccagdldgiimedpiccmgmiedagg4
17921789
dlddmedljhmbgdhapibnagaanenmajcm
17931790
bbgbmlkfflffccognkcbbmkakbejnado
17941791
bcmmbhidjmodkbeidljmhcijhkchokcj

feeds/ioc_malicious_extension_ids.txt

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -109,10 +109,8 @@ phfkdailnomcbcknpdmokejhellbecjb
109109
pkghgkfjhjghinikeanecbgjehojfhdg
110110
pllkanemicadpcmkfodglahcocfdgkhj
111111
jnannpdmmiphnkpaooplhegabbghlplj
112-
ipmmidjikiklckbngllogmggoofbhjikgb
113112
gogbiohkminacikoppmljeolgccpmlop
114113
bcjindcccaagfpapjjmafapmmgkkhgoa
115-
plfchpahihleeejpjmodggckakhglee
116114
ckkjdiimhlanonhceggkfjlmjnenpmfm
117115
fpeabamapgecnidibdmjoepaiehokgda
118116
ajfanjhcdgaohcbphpaceglgpgaaohod
@@ -1689,7 +1687,6 @@ oejfpkocfgochpkljdlmcnibecancpnl
16891687
olkcbimhgpenhcboejacjpmohcincfdb
16901688
ooaehdahoiljphlijlaplnbeaeeimhbb
16911689
pidecdgcabcolloikegacdjejomeodji
1692-
nmmhkkegccagdldgiimedpiccmgmiedagg4
16931690
dlddmedljhmbgdhapibnagaanenmajcm
16941691
bbgbmlkfflffccognkcbbmkakbejnado
16951692
bcmmbhidjmodkbeidljmhcijhkchokcj

0 commit comments

Comments
 (0)