T1176Software Extensions
T1176 — Software Extensions is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 12 detection use cases covering it and 46 threat-intel articles citing it.
Persistence
12Use cases
46Articles
2Sub-techniques
1Tactic
Sub-techniques (2)
Use cases covering this technique (12)
Suspicious browser extension installation [LLM] Browser egress to Myxa SOCKS5 proxy infrastructure (known IPs) [LLM] DNS/connection to Myxa fake-VPN impersonation domains [LLM] Browser-initiated SOCKS5 to TCP/1082 — new proxy infrastructure [LLM] External browser process connects to SiYuan kernel loopback admin port 127.0.0.1:6806 [LLM] Browser extension manifest rewritten adding networking/host permissions (supply-chain) [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro [LLM] VS Code child process fetching payload from nrwl/nx orphan commit (Nx Console v18.95.0 dropper) [LLM] Context.ai compromised Chrome extension (ID omddlmnhcofjbnbflmjginpjjblphbgk) present on endpoint [LLM] Cyberhaven compromised extension C2 beacon to cyberhavenext[.]pro [LLM] Solidity Language malicious Cursor/VS Code extension folder created on disk (solidityai.solidity-* and related) [LLM] Browser extension folder write at vulnerable React DevTools 4.27.8 / Vue.js devtools 6.5.0Articles citing this technique (46)
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
crit The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications art-96
crit ESET Threat Report H1 2026 art-312
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-458
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-486
crit Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks art-499
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-597