BSides London 2025

BSides London 2025

Beginner’s Guide to Malicious Browser Extensions
2025-12-13 , Rookie Track 1

Software beginners often assume that installing a browser extension is harmless. However, recent incidents reveal even widely-used extensions can deliver spyware, hijack sessions, or steal credentials. This rookie-friendly talk examines a malicious network of Firefox and Chrome extensions impersonating popular games that hijacked sessions, redirected users to scams, and stole sensitive credentials. We’ll demystify browser extension threats and share a simple checklist for evaluating extensions. In just 15 minutes, attendees will learn easy habits to keep their browsers safe without specialized tools.


  1. Why browser extension security matters (3 min)

Introduce browser extensions and their common uses.

Summarize recent incidents involving malicious gaming extensions that hijacked sessions and stole credentials.

  1. Common browser extension threats explained (5 min)

Impersonation: How attackers create extensions posing as popular games to deceive users.

Hijacking and credential theft: Demonstrate simple methods attackers use to gain unauthorized access or redirect users.

  1. Simple security checklist for beginners (5 min)

  2. Wrap-up and invitation to explore further (2 min)

Encourage continuous learning about browser security.


Please confirm that I am a first time speaker and have not spoken in public and will not be before the Bsides London event date (14th December 2024).: Yes

Kush Pandya – Security researcher at Socket.dev