Open-source malicious browser-extension analysis platform
A tool for malware analysts, threat researchers, blue teams, and enterprise security teams that automates browser-extension investigation. It unpacks extensions, analyzes files and permissions, applies custom static-analysis rules, enriches findings with external intelligence, and uses AI to combine the evidence into an explanation, recommendation, and risk score.
From IBM Technology — Why won’t AI agents just follow the rules? at 29:01
Problem: Browser extensions can appear legitimate while requesting powerful permissions, accessing web pages, collecting credentials, reading browser activity, changing what users see, or hiding credential theft and data collection in their code. Manual investigation is time-consuming, and malicious extensions may disappear from the web store after detection.
For: Malware analysts, threat researchers, blue teams, and enterprise security teams that need to evaluate browser extensions before allowing employees to use them.
Products from this video
Examples
- Extensions mimicking PDF readers: can appear useful or trustworthy while requesting powerful browser permissions.