PEEP: Chromium post-exploit toolkit via Smart Bookmarks extension (SOCRadar)
SOCRadar (covered by The Hacker News, ~7 September 2026) documents PEEP, a Chromium-based post-exploitation toolkit that requires prior admin or code-execution access. An installer injects a malicious extension masquerading as "Smart Bookmarks" into Chrome/Edge profiles; the extension (based on the open-source RedExt framework) beacons for commands, harvests browser data, and uses a native messaging host (nm_host.exe) for host-level command execution and file management. Chinese-language artifacts in the source point to a Chinese-speaking actor; activity remains unattributed. Distinct from browser-infostealer cards: this is a post-compromise backdoor, not an initial-access drop. Primary wire: The Hacker News; research: SOCRadar.
- Product
- Google Chrome / Microsoft Edge (Chromium) post-compromise
- Exploited in Australia?
- unknown
- Patch to
- Hunt unexpected Smart Bookmarks extension and nm_host.exe native messaging hosts; treat forged Secure Preferences integrity as hostile
Primary: The Hacker News — PEEP Chromium toolkit (~7 Sep 2026) · Vendor: SOCRadar — PEEP browser RAT / Chrome extension
