Skip to content

Commit 619aaf6

Browse files
chore: update feeds 2026-04-02
1 parent d0d763c commit 619aaf6

14 files changed

Lines changed: 12201 additions & 12241 deletions

browser_extensions_list.csv

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
browser_extension,browser_extension_id_wildcard,browser_extension_id,metadata_category,metadata_type,metadata_link,metadata_comment,crx_file_sha256
2-
"JSON Formatter","*bcjindcccaagfpapjjmafapmmgkkhgoa*","bcjindcccaagfpapjjmafapmmgkkhgoa","adware","suspicious","https://chromewebstore.google.com/detail/json-formatter/bcjindcccaagfpapjjmafapmmgkkhgoa/reviews","https://x.com/wesbos/status/2039355472830939319?s=20",""
2+
"JSON Formatter","*bcjindcccaagfpapjjmafapmmgkkhgoa*","bcjindcccaagfpapjjmafapmmgkkhgoa","PUP","suspicious","https://chromewebstore.google.com/detail/json-formatter/bcjindcccaagfpapjjmafapmmgkkhgoa/reviews","https://x.com/wesbos/status/2039355472830939319?s=20",""
33
"","*nplfchpahihleeejpjmodggckakhglee*","plfchpahihleeejpjmodggckakhglee","malware","malicious","https://x.com/i/status/1907925793336078675","bank credential stealer",""
44
"","*ckkjdiimhlanonhceggkfjlmjnenpmfm*","ckkjdiimhlanonhceggkfjlmjnenpmfm","malware","malicious","https://x.com/i/status/1907925793336078675","bank credential stealer",""
55
"Chrome MCP Server - AI Browser Control","*fpeabamapgecnidibdmjoepaiehokgda*","fpeabamapgecnidibdmjoepaiehokgda","malware","malicious","https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/dbdcea6a9f5684a9268c39e60c667c5c9c06263b/2026-02-11-IOCs-for-RAT-disguinsed-as-AI-based-browser-extension.txt","RAT AI browser extension","0cbf101e96f6d5c4146812f07105f8b89bd76dd994f540470cd1c4bc37df37d5"

feeds/elastic_threat_intel.ndjson

Lines changed: 1416 additions & 1416 deletions
Large diffs are not rendered by default.

feeds/extsentry_feed.json

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,20 +1,19 @@
11
{
22
"feed_name": "ExtSentry - Browser Extension Threat Intelligence",
33
"feed_version": "1.0",
4-
"generated": "2026-04-02T09:42:50Z",
4+
"generated": "2026-04-02T10:36:08Z",
55
"source": "https://github.com/mthcht/awesome-lists",
66
"license": "TLP:CLEAR",
77
"total_indicators": 1416,
88
"categories": {
9-
"adware": 1,
9+
"PUP": 4,
1010
"malware": 1178,
1111
"compromised": 94,
1212
"cryptocurrency": 117,
1313
"Credential Access": 2,
1414
"Defense Evasion": 1,
1515
"scam": 5,
1616
"RMM": 1,
17-
"PUP": 3,
1817
"password manager": 9,
1918
"PROXY/VPN": 5
2019
},
@@ -23,7 +22,7 @@
2322
"extension_id": "bcjindcccaagfpapjjmafapmmgkkhgoa",
2423
"extension_name": "JSON Formatter",
2524
"wildcard_pattern": "*bcjindcccaagfpapjjmafapmmgkkhgoa*",
26-
"category": "adware",
25+
"category": "PUP",
2726
"threat_type": "suspicious",
2827
"reference_url": "https://chromewebstore.google.com/detail/json-formatter/bcjindcccaagfpapjjmafapmmgkkhgoa/reviews",
2928
"description": "https://x.com/wesbos/status/2039355472830939319?s=20",

feeds/extsentry_ioc_feed.csv

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
extension_id,extension_name,wildcard_pattern,category,threat_type,reference_url,description,chrome_webstore_url,severity,crx_sha256,first_seen,feed_source
2-
bcjindcccaagfpapjjmafapmmgkkhgoa,JSON Formatter,*bcjindcccaagfpapjjmafapmmgkkhgoa*,adware,suspicious,https://chromewebstore.google.com/detail/json-formatter/bcjindcccaagfpapjjmafapmmgkkhgoa/reviews,https://x.com/wesbos/status/2039355472830939319?s=20,https://chromewebstore.google.com/detail/bcjindcccaagfpapjjmafapmmgkkhgoa,medium,,2026-04-02,ExtSentry (github.com/mthcht/awesome-lists)
2+
bcjindcccaagfpapjjmafapmmgkkhgoa,JSON Formatter,*bcjindcccaagfpapjjmafapmmgkkhgoa*,PUP,suspicious,https://chromewebstore.google.com/detail/json-formatter/bcjindcccaagfpapjjmafapmmgkkhgoa/reviews,https://x.com/wesbos/status/2039355472830939319?s=20,https://chromewebstore.google.com/detail/bcjindcccaagfpapjjmafapmmgkkhgoa,medium,,2026-04-02,ExtSentry (github.com/mthcht/awesome-lists)
33
plfchpahihleeejpjmodggckakhglee,bank credential stealer,*nplfchpahihleeejpjmodggckakhglee*,malware,malicious,https://x.com/i/status/1907925793336078675,bank credential stealer,https://chromewebstore.google.com/detail/plfchpahihleeejpjmodggckakhglee,critical,,2026-04-02,ExtSentry (github.com/mthcht/awesome-lists)
44
ckkjdiimhlanonhceggkfjlmjnenpmfm,bank credential stealer,*ckkjdiimhlanonhceggkfjlmjnenpmfm*,malware,malicious,https://x.com/i/status/1907925793336078675,bank credential stealer,https://chromewebstore.google.com/detail/ckkjdiimhlanonhceggkfjlmjnenpmfm,critical,,2026-04-02,ExtSentry (github.com/mthcht/awesome-lists)
55
fpeabamapgecnidibdmjoepaiehokgda,Chrome MCP Server - AI Browser Control,*fpeabamapgecnidibdmjoepaiehokgda*,malware,malicious,https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/dbdcea6a9f5684a9268c39e60c667c5c9c06263b/2026-02-11-IOCs-for-RAT-disguinsed-as-AI-based-browser-extension.txt,RAT AI browser extension,https://chromewebstore.google.com/detail/fpeabamapgecnidibdmjoepaiehokgda,critical,0cbf101e96f6d5c4146812f07105f8b89bd76dd994f540470cd1c4bc37df37d5,2026-04-02,ExtSentry (github.com/mthcht/awesome-lists)

feeds/misp_event.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"analysis": "2",
66
"distribution": "3",
77
"date": "2026-04-02",
8-
"timestamp": "1775122971",
8+
"timestamp": "1775126169",
99
"published": false,
1010
"uuid": "41ef2090-fab5-547e-9eb6-2aa8f195c66f",
1111
"Orgc": {
@@ -33,11 +33,11 @@
3333
"category": "Other",
3434
"to_ids": false,
3535
"value": "bcjindcccaagfpapjjmafapmmgkkhgoa",
36-
"comment": "JSON Formatter | Category: adware | Type: suspicious | https://x.com/wesbos/status/2039355472830939319?s=20",
36+
"comment": "JSON Formatter | Category: PUP | Type: suspicious | https://x.com/wesbos/status/2039355472830939319?s=20",
3737
"distribution": "5",
3838
"Tag": [
3939
{
40-
"name": "extsentry:category=\"adware\""
40+
"name": "extsentry:category=\"PUP\""
4141
},
4242
{
4343
"name": "extsentry:type=\"suspicious\""
@@ -24245,7 +24245,7 @@
2424524245
{
2424624246
"object_relation": "text",
2424724247
"type": "text",
24248-
"value": "adware",
24248+
"value": "PUP",
2424924249
"comment": "Threat Category",
2425024250
"to_ids": false
2425124251
},

0 commit comments

Comments
 (0)