PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
- ID
- 22166
- Status
- summarized
- Published
- 08 Sep 2026, 2:12 AM
- Fetched
- 08 Sep 2026, 3:16 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 08 Sep 2026, 3:20 AM
- Tags
- Audience
- developersai_agent_users
What happened
SOCRadar disclosed PEEP, a post-exploitation toolkit that injects a fake 'Smart Bookmarks' extension (ID: ejkndncpkdcjcikfhiamcdehdoegilbj) directly into Chrome/Edge profiles by forging Chromium's Secure Preferences integrity values, bypassing Web Store checks entirely. A native messaging host binary (nm_host.exe) escalates it from credential theft to full host-level command execution, polling a C2 server every 30 seconds over plaintext HTTP. PEEP is built on the open-source RedExt red-teaming framework and contains Chinese-language source artifacts, though attribution remains unconfirmed.
Why it matters
If you ship Chromium extensions or use the Native Messaging Host API, this demonstrates a concrete attack path where your extension architecture can be weaponized post-compromise — review whether your native messaging binaries validate caller identity and whether your extension loading process can be subverted via profile injection. For everyone else, this is a reminder that browser extensions are a persistent foothold: treat endpoint compromise as browser compromise, since PEEP harvests session cookies and can inject JavaScript into active tabs.
Discussion angle
The Native Messaging Host API is the real escalation story here — it's the same legitimate mechanism many dev tools and AI agents use to bridge browser extensions to local processes. Discuss whether your own native messaging integrations could be abused if an attacker gained profile-level access, and what integrity checks (if any) Chromium actually enforces on injected extensions.