A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already there.Nothing here needed magic. Mostly access, trust, weak edges, and someone willing to keep poking. That’s the week.The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

Malicious extensions steal crypto data

A set of four malicious Google Chrome and Mozilla Firefox extensions has been found to target Axiom Trade and Padre users to steal session tokens and wallet data. The extensions are J7Tracker (Chrome), VREO (Chrome and Firefox), and Orbit Tracker (Firefox). While the first three contain the same Axiom and Padre collection module, the fourth implements a different collector but targets the same data, while retaining some artifacts from J7Tracker. "The module is byte-identical across all three analyzed extensions. It automatically retrieves authenticated user information, wallet-related bundle data, Firebase access tokens, and application state, then sends the information to threat actor-controlled Vercel deployments," Socket said. The same Chrome publisher has been traced back to two earlier extensions, GhostApe and GhostApe Color, impersonating the MockApe trading add-on.