Saturday 05 September 2026 04:51:58 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

WIKICROOK

Extension spoofing

Publishing lookalike add-ons to impersonate trusted tools.

Extension spoofing is the practice of publishing lookalike add-ons that impersonate trusted tools. The goal is to make users install a malicious or unwanted package because its name, icon, description, or namespace resembles a legitimate extension they already know.

This matters because extensions often run with access to editor settings, local files, terminals, or development workflows. In an attack, spoofed packages can steal data, redirect updates, or create a foothold inside a developer machine. Defenders look for publisher mismatches, unusual naming patterns, copied descriptions, suspicious permissions, and shared infrastructure across multiple packages. Strong review processes, provenance checks, and allowlists reduce the chance that a convincing fake will be trusted simply because it looks familiar.

← WIKICROOK index