Reddit
ShotBird Malware Campaign: Browser Extension Compromise and Host Malware Delivery
First seen 8 Mar 2026, 19:09 UTC
•
•33.4
Export
Article Content
Browse articles
The ShotBird campaign involves a supply-chain compromise of a Chrome extension, leading to malware delivery on user endpoints. Victims are primarily users of the affected browser extension, which delivered a PowerShell stager to facilitate further attacks. Technical details reveal the use of fake updates to propagate the malware.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-03-08
ShotBird malware campaign reported on Reddit
Date unknown
Browser extension compromised for malware delivery
Date unknown
PowerShell stager reconstructed for further exploitation
More articles in this cluster
Continue Reading
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
SHADOW-EARTH-053 Exploits Microsoft Exchange Vulnerabilities in Asia
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign