PEEP Chrome Extension Enables Credential Theft and Shell Command Execution

PEEP Chrome Extension Enables Credential Theft and Shell Command Execution

First seen 7 Sep 2026, 19:03 UTC Gbhackersunderdefense.comThehackernews 71.5

Article Content

Browse articles
ThreatCluster

A new post-exploitation toolkit named PEEP has been identified, affecting Google Chrome and Microsoft Edge. This toolkit masquerades as a benign bookmarks extension, requiring prior administrative or code execution access to install. Once active, PEEP can steal browser data, hijack sessions, and execute shell commands on compromised systems. It operates by injecting itself into browser profiles and bypassing Web Store checks. The toolkit communicates with a command-and-control server every 30 seconds, exfiltrating sensitive data like session cookies and browsing history. PEEP is derived from the RedExt framework and has capabilities for file management and command execution beyond the browser. The presence of Chinese-language artifacts in the code suggests a potential link to Chinese-speaking threat actors. SOCRadar discovered the toolkit, which has been reported but remains unattributed.

Key Points: • PEEP requires prior administrative access to install and operates as a browser extension. • The toolkit can steal sensitive data and execute commands outside the browser sandbox. • Chinese-language artifacts in the code hint at a potential link to Chinese-speaking threat actors.

Ask AI about this cluster

Timeline

2026-09-04
CVE-2026-75754 published
A vulnerability related to the PEEP toolkit was published, highlighting its capabilities and risks.
Gbhackers
2026-09-07
PEEP toolkit disclosed
Cybersecurity researchers disclosed the PEEP toolkit, detailing its operation and capabilities.
Thehackernews