NPM attack targets Zapier and security tool browser extensions

5 pointsposted 10 hours ago
by 6mile

1 Comments

6mile

10 hours ago

NPM attack targeting Mastro targets browser extensions other than crypto wallets.

- Credential managers and MFA authenticators from LastPass, Bitwarden, 1Password, Deloitte, Dashlane, ExpressVPN, KeePass, Proton, Kaspersky, passbolt, NordPass, Zoho, etc. - Zapier browser extension. Assuming this is to gain access to platforms the victim has integrated with Zapier