Threat Intelligence

PEEP hijacks Chrome and Edge via forged extension profiles

⏱️ 3 min read📅 9/8/2026👁️ 24 views

PEEP hijacks Chrome and Edge via forged extension profiles

The installer slips a “Smart Bookmarks” extension (ID ejkndncpkdcjcikfhiamcdehdoegilbj) straight into Chrome and Edge profiles by corrupting Chromium’s Secure Preferences integrity values. No Web Store approval, no user prompt – just a silent takeover.

Why it matters

Once the extension is in place, the browser becomes a foothold for a full‑blown backdoor. The toolkit can run native commands on the host, pull files, and ship browsing data back to the attacker every half‑minute.

Technical walk‑through

The extension talks to two hard‑coded C2 servers (206.237.30.232 and xfjcc.fun) over clear‑text HTTP, polling every 30 seconds. It uses a native‑messaging host (nm_host.exe) to break out of the browser sandbox and execute host‑level PowerShell scripts.

  • PowerShell helpers: install_silent.ps1, patch_secure_prefs.ps1, force_enable.ps1 – enable developer mode, patch Secure Preferences, force‑install the extension.
  • Linux counterpart: patch_secure_prefs_linux.py shows the same technique works on Chromium on Linux.
  • API endpoints used for registration, telemetry and exfiltration:
    /api/register, /api/agents/<id>/heartbeat, /api/extension_update/, /api/extension_crx/, /api/agents/<id>/task_result, /api/exfil, /health, /login

The toolkit harvests browsing history, active‑tab metadata, session cookies, public IP, locale and timezone data, then ships it back via the /api/exfil endpoint.

Who’s at risk

Any workstation running Google Chrome or Microsoft Edge on Windows or Linux can be compromised if the attacker can write to the user’s profile directory. Enterprise environments that use force‑install policies are especially vulnerable because the same sideloading technique can be baked into group policy.

Defensive steps

  1. Audit the Secure Preferences file for unexpected modifications or mismatched integrity hashes.
  2. Search for the extension ID ejkndncpkdcjcikfhiamcdehdoegilbj in all user profiles; remove any stray entries.
  3. Block outbound HTTP to 206.237.30.232 and xfjcc.fun at the network perimeter.
  4. Disable native‑messaging hosts that you do not explicitly need; monitor for newly registered nm_host.exe binaries.
  5. Review group‑policy and enterprise force‑install settings for unknown extensions.
  6. Run endpoint detection rules that flag PowerShell scripts named install_silent.ps1, patch_secure_prefs.ps1 or force_enable.ps1 executing in user contexts.

Detecting the toolkit early hinges on spotting the odd combination of a browser extension and a native‑messaging host that talks to known C2 IPs. Once you’ve cleared the extension and its host, rotate any potentially exposed credentials and session cookies.

#Chromium#Browser Extension#Post-Exploitation#Native Messaging#Persistence