What happened: Microsoft pulled 119 extensions from the Edge store tied to a single malware campaign nicknamed “StegoAd” — installed by roughly 2.6 million people. They posed as ordinary tools (ad blockers, VPNs, translators, video downloaders) and worked normally for a while, then “woke up” and started stealing: Google sign-in credentials and two-factor codes, session cookies for account hijacking, and — notably — WordPress admin logins. The same techniques work on any Chromium browser, not just Edge.
Why it matters to your business
Every extension your staff installs is a small program that can watch everything they do online — including logging into your business systems, email, and website. This campaign specifically harvested website admin credentials, which is exactly how a small business ends up with its own site defaced or used to attack its customers. And it hid by only activating on about 1 in 10 installs, so “it seems fine” means nothing.
What to do this week
Audit browser extensions on company machines and remove anything nobody can justify. Set a simple rule: no new extensions without approval, and judge by the developer’s reputation, not the star rating (fakes buy good reviews). If staff use Google or WordPress logins, rotating passwords and confirming two-factor is on is cheap insurance.
The bigger picture
This is the quiet version of the same threat we write about constantly: attackers don’t break the door down, they get an employee to hold it open. The defense isn’t a product — it’s knowing which everyday actions carry risk and having a policy for them: Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back.