Skip to main content
← Back to Demos
SBOM intermediate · 15 min

Malicious npm Dependency Powering Wallet-Draining Browser Extensions (2026-08-29 CISO Daily Digest)

This demo reproduces that supply-chain foothold safely: a synthetic `malicious-package.json` stands in for an extension's build manifest that pins known-vulnerable dependency versions — `lodash` 4.17.20, `minimist` 1.2.5, `async` 2.6.3 (each with publicly-known CVEs) — while the `clean-package.json` counterpart pins only a vetted, patched component (`lodash` 4.17.21). Nothing is executed and no real keys are touched; the only effect is to show how a vulnerable dependency enters the build tree. OPSWAT SBOM analysis inspects the dependency tree BEFORE the artifact ships, identifies the vulnerable / compromised components (the T1195.001 supply-chain foothold), and blocks them — so a wallet-draining extension never reaches end users (MITRE ATT&CK T1195.001 Supply Chain Compromise: Software Dependencies and Development Tools).

Attack Technique

Compromise of software dependencies — a build manifest (malicious-package.json) pinning known-vulnerable npm packages (lodash 4.17.20, minimist 1.2.5, async 2.6.3), the T1195.001 supply-chain foothold that lets wallet-draining code reach an extension's users (T1195.001 Supply Chain Compromise: Software Dependencies and Development Tools)

MITRE ATT&CK

T1195.001 ↗

Platforms

linux

File Types

.json.zip

MetaDefender Capabilities

SBOM

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---