Skip to content

Commit 0437032

Browse files
chore: update feeds 2026-04-02
1 parent 63a6c4f commit 0437032

18 files changed

Lines changed: 13785 additions & 13611 deletions

browser_extensions_list.csv

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
browser_extension,browser_extension_id_wildcard,browser_extension_id,metadata_category,metadata_type,metadata_link,metadata_comment,crx_file_sha256
2+
"JSON Formatter","*bcjindcccaagfpapjjmafapmmgkkhgoa*","bcjindcccaagfpapjjmafapmmgkkhgoa","adware","suspicious","https://chromewebstore.google.com/detail/json-formatter/bcjindcccaagfpapjjmafapmmgkkhgoa/reviews","https://x.com/wesbos/status/2039355472830939319?s=20",""
23
"","*nplfchpahihleeejpjmodggckakhglee*","plfchpahihleeejpjmodggckakhglee","malware","malicious","https://x.com/i/status/1907925793336078675","bank credential stealer",""
34
"","*ckkjdiimhlanonhceggkfjlmjnenpmfm*","ckkjdiimhlanonhceggkfjlmjnenpmfm","malware","malicious","https://x.com/i/status/1907925793336078675","bank credential stealer",""
45
"Chrome MCP Server - AI Browser Control","*fpeabamapgecnidibdmjoepaiehokgda*","fpeabamapgecnidibdmjoepaiehokgda","malware","malicious","https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/dbdcea6a9f5684a9268c39e60c667c5c9c06263b/2026-02-11-IOCs-for-RAT-disguinsed-as-AI-based-browser-extension.txt","RAT AI browser extension","0cbf101e96f6d5c4146812f07105f8b89bd76dd994f540470cd1c4bc37df37d5"

feeds/elastic_detection_rule.ndjson

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

feeds/elastic_threat_intel.ndjson

Lines changed: 1416 additions & 1415 deletions
Large diffs are not rendered by default.

feeds/extsentry_feed.json

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,12 @@
11
{
22
"feed_name": "ExtSentry - Browser Extension Threat Intelligence",
33
"feed_version": "1.0",
4-
"generated": "2026-04-02T08:02:24Z",
4+
"generated": "2026-04-02T09:32:51Z",
55
"source": "https://github.com/mthcht/awesome-lists",
66
"license": "TLP:CLEAR",
7-
"total_indicators": 1415,
7+
"total_indicators": 1416,
88
"categories": {
9+
"adware": 1,
910
"malware": 1178,
1011
"compromised": 94,
1112
"cryptocurrency": 117,
@@ -18,6 +19,17 @@
1819
"PROXY/VPN": 5
1920
},
2021
"indicators": [
22+
{
23+
"extension_id": "bcjindcccaagfpapjjmafapmmgkkhgoa",
24+
"extension_name": "JSON Formatter",
25+
"wildcard_pattern": "*bcjindcccaagfpapjjmafapmmgkkhgoa*",
26+
"category": "adware",
27+
"threat_type": "suspicious",
28+
"reference_url": "https://chromewebstore.google.com/detail/json-formatter/bcjindcccaagfpapjjmafapmmgkkhgoa/reviews",
29+
"description": "https://x.com/wesbos/status/2039355472830939319?s=20",
30+
"crx_sha256": null,
31+
"chrome_webstore_url": "https://chromewebstore.google.com/detail/bcjindcccaagfpapjjmafapmmgkkhgoa"
32+
},
2133
{
2234
"extension_id": "plfchpahihleeejpjmodggckakhglee",
2335
"extension_name": null,

feeds/extsentry_ioc_feed.csv

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
extension_id,extension_name,wildcard_pattern,category,threat_type,reference_url,description,chrome_webstore_url,severity,crx_sha256,first_seen,feed_source
2+
bcjindcccaagfpapjjmafapmmgkkhgoa,JSON Formatter,*bcjindcccaagfpapjjmafapmmgkkhgoa*,adware,suspicious,https://chromewebstore.google.com/detail/json-formatter/bcjindcccaagfpapjjmafapmmgkkhgoa/reviews,https://x.com/wesbos/status/2039355472830939319?s=20,https://chromewebstore.google.com/detail/bcjindcccaagfpapjjmafapmmgkkhgoa,medium,,2026-04-02,ExtSentry (github.com/mthcht/awesome-lists)
23
plfchpahihleeejpjmodggckakhglee,bank credential stealer,*nplfchpahihleeejpjmodggckakhglee*,malware,malicious,https://x.com/i/status/1907925793336078675,bank credential stealer,https://chromewebstore.google.com/detail/plfchpahihleeejpjmodggckakhglee,critical,,2026-04-02,ExtSentry (github.com/mthcht/awesome-lists)
34
ckkjdiimhlanonhceggkfjlmjnenpmfm,bank credential stealer,*ckkjdiimhlanonhceggkfjlmjnenpmfm*,malware,malicious,https://x.com/i/status/1907925793336078675,bank credential stealer,https://chromewebstore.google.com/detail/ckkjdiimhlanonhceggkfjlmjnenpmfm,critical,,2026-04-02,ExtSentry (github.com/mthcht/awesome-lists)
45
fpeabamapgecnidibdmjoepaiehokgda,Chrome MCP Server - AI Browser Control,*fpeabamapgecnidibdmjoepaiehokgda*,malware,malicious,https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/dbdcea6a9f5684a9268c39e60c667c5c9c06263b/2026-02-11-IOCs-for-RAT-disguinsed-as-AI-based-browser-extension.txt,RAT AI browser extension,https://chromewebstore.google.com/detail/fpeabamapgecnidibdmjoepaiehokgda,critical,0cbf101e96f6d5c4146812f07105f8b89bd76dd994f540470cd1c4bc37df37d5,2026-04-02,ExtSentry (github.com/mthcht/awesome-lists)

feeds/ioc_all_extension_ids.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
bcjindcccaagfpapjjmafapmmgkkhgoa
12
plfchpahihleeejpjmodggckakhglee
23
ckkjdiimhlanonhceggkfjlmjnenpmfm
34
fpeabamapgecnidibdmjoepaiehokgda

feeds/ioc_suspicious_extension_ids.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
bcjindcccaagfpapjjmafapmmgkkhgoa
12
fhbohimaelbohpjbbldcngcnapnedx765dodjp
23
fnjhmkhhmkbedx765jkkabndcnnogagogbneec
34
akoofbljmjeodfmdpjndmmnifglppjdi

feeds/misp_event.json

Lines changed: 63 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"analysis": "2",
66
"distribution": "3",
77
"date": "2026-04-02",
8-
"timestamp": "1775116944",
8+
"timestamp": "1775122371",
99
"published": false,
1010
"uuid": "41ef2090-fab5-547e-9eb6-2aa8f195c66f",
1111
"Orgc": {
@@ -27,6 +27,23 @@
2727
}
2828
],
2929
"Attribute": [
30+
{
31+
"uuid": "56dfb3e2-4de5-5709-9dce-5c48a471bef4",
32+
"type": "text",
33+
"category": "Other",
34+
"to_ids": false,
35+
"value": "bcjindcccaagfpapjjmafapmmgkkhgoa",
36+
"comment": "JSON Formatter | Category: adware | Type: suspicious | https://x.com/wesbos/status/2039355472830939319?s=20",
37+
"distribution": "5",
38+
"Tag": [
39+
{
40+
"name": "extsentry:category=\"adware\""
41+
},
42+
{
43+
"name": "extsentry:type=\"suspicious\""
44+
}
45+
]
46+
},
3047
{
3148
"uuid": "e4d6c6c1-7172-52e5-a3a4-8265966bcef8",
3249
"type": "text",
@@ -24203,6 +24220,51 @@
2420324220
}
2420424221
],
2420524222
"Object": [
24223+
{
24224+
"uuid": "92657467-7e91-5ff4-90bd-db002313bbdd",
24225+
"name": "annotation",
24226+
"meta-category": "misc",
24227+
"description": "Suspicious/Malicious browser extension: JSON Formatter",
24228+
"template_uuid": "e434b304-a905-53fb-b7df-1d552e338795",
24229+
"template_version": "1",
24230+
"Attribute": [
24231+
{
24232+
"object_relation": "text",
24233+
"type": "text",
24234+
"value": "bcjindcccaagfpapjjmafapmmgkkhgoa",
24235+
"comment": "Browser Extension ID",
24236+
"to_ids": false
24237+
},
24238+
{
24239+
"object_relation": "text",
24240+
"type": "text",
24241+
"value": "JSON Formatter",
24242+
"comment": "Extension Name",
24243+
"to_ids": false
24244+
},
24245+
{
24246+
"object_relation": "text",
24247+
"type": "text",
24248+
"value": "adware",
24249+
"comment": "Threat Category",
24250+
"to_ids": false
24251+
},
24252+
{
24253+
"object_relation": "text",
24254+
"type": "text",
24255+
"value": "suspicious",
24256+
"comment": "Threat Type",
24257+
"to_ids": false
24258+
},
24259+
{
24260+
"object_relation": "text",
24261+
"type": "link",
24262+
"value": "https://chromewebstore.google.com/detail/json-formatter/bcjindcccaagfpapjjmafapmmgkkhgoa/reviews",
24263+
"comment": "Reference URL",
24264+
"to_ids": false
24265+
}
24266+
]
24267+
},
2420624268
{
2420724269
"uuid": "99b8c136-8de4-5da5-aaca-d2875d8ac296",
2420824270
"name": "annotation",

feeds/misp_warninglist.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@
99
"other"
1010
],
1111
"list": [
12+
"bcjindcccaagfpapjjmafapmmgkkhgoa",
1213
"plfchpahihleeejpjmodggckakhglee",
1314
"ckkjdiimhlanonhceggkfjlmjnenpmfm",
1415
"fpeabamapgecnidibdmjoepaiehokgda",

0 commit comments

Comments
 (0)