Malicious npm Dependency Powering Wallet-Draining Browser Extensions (2026-08-29 CISO Daily Digest)
This demo reproduces that supply-chain foothold safely: a synthetic `malicious-package.json` stands in for an extension's build manifest that pins known-vulnerable dependency versions — `lodash` 4.17.20, `minimist` 1.2.5, `async` 2.6.3 (each with publicly-known CVEs) — while the `clean-package.json` counterpart pins only a vetted, patched component (`lodash` 4.17.21). Nothing is executed and no real keys are touched; the only effect is to show how a vulnerable dependency enters the build tree. OPSWAT SBOM analysis inspects the dependency tree BEFORE the artifact ships, identifies the vulnerable / compromised components (the T1195.001 supply-chain foothold), and blocks them — so a wallet-draining extension never reaches end users (MITRE ATT&CK T1195.001 Supply Chain Compromise: Software Dependencies and Development Tools).
Attack Technique
Compromise of software dependencies — a build manifest (malicious-package.json) pinning known-vulnerable npm packages (lodash 4.17.20, minimist 1.2.5, async 2.6.3), the T1195.001 supply-chain foothold that lets wallet-draining code reach an extension's users (T1195.001 Supply Chain Compromise: Software Dependencies and Development Tools)
MITRE ATT&CK
T1195.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗