ShotBird Malware Campaign: Browser Extension Compromise and Host Malware Delivery

ShotBird Malware Campaign: Browser Extension Compromise and Host Malware Delivery

First seen 8 Mar 2026, 19:09 UTC Reddit 33.4

Article Content

Browse articles
ThreatCluster

The ShotBird campaign involves a supply-chain compromise of a Chrome extension, leading to malware delivery on user endpoints. Victims are primarily users of the affected browser extension, which delivered a PowerShell stager to facilitate further attacks. Technical details reveal the use of fake updates to propagate the malware.

Timeline

2026-03-08
ShotBird malware campaign reported on Reddit
Date unknown
Browser extension compromised for malware delivery
Date unknown
PowerShell stager reconstructed for further exploitation