Threat reportMalwareTL-2026-2380
PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
PEEP: Chromium Toolkit Turns Chrome and Edge Into (TL-2026-2380), also tracked as Smart Bookmarks, is a high-severity malware campaign, first published 2026-09-07. It has no confirmed attribution, affects Google Google Chrome, maps to 14 MITRE ATT&CK techniques (T1005, T1007, T1036), and is covered by 9 detection rules and 26 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-2380
- Threat ID
- TL-2026-2380
- Also known as
- Smart Bookmarks
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in PEEP: Chromium Toolkit Turns Chrome and Edge Into
Malware and tooling: PEEP, RedExt, RedExt/Flask-SQLite C2, com.peep.lab
How PEEP: Chromium Toolkit Turns Chrome and Edge Into works
PEEP is a Chromium-based post-exploitation toolkit that masquerades as a 'Smart Bookmarks' browser extension (ID ejkndncpkdcjcikfhiamcdehdoegilbj) and abuses a native-messaging host binary (nm_host.exe, registered as com.peep.lab) to escape the browser sandbox. It enables host command execution, session-cookie theft (bypassing MFA), file management, process/service discovery, and data exfiltration on Chrome and Edge, and is being adapted for Linux. Discovered by SOCRadar (September 2026) with a live C2 panel observed (34 agent entries, ~10 active sessions, 507 data records), the toolkit is unattributed although Chinese-language artifacts in its source point to a Chinese-speaking operator.
PEEP is a modular browser RAT derived from the open-source RedExt C2 framework (Manifest V3 Chrome extension + Flask/SQLite control panel, authored for legitimate red-team work) and weaponized into an operational post-exploitation toolkit. It is strictly a post-compromise framework: it has no initial access vector of its own and requires the operator to already possess administrative privileges or prior code execution on the target before installation. SOCRadar observed this active at the time of analysis: the C2 host resolved to 206.237.30.232 (AS55933, Cloudie Limited, Hong Kong) with domains xfjcc.fun and subdomains new, newadmin, and newapi; TCP 5002 exposed a development repository containing source code, builds, logs, utilities, and the private key for the primary extension identity, while the unauthenticated /health endpoint on the port-5001 control panel showed 34 agent entries, roughly 10 active sessions, and 507 stored data records (test entries cannot be differentiated from real infections). The control panel is a Flask-and-SQLite C2 application (consistent with its RedExt lineage) reached over plaintext HTTP on port 5001; agent requests carry the custom headers X-PEEP-Agent-Key and X-PEEP-Agent-Id, and authenticated responses use the realm="PEEP" challenge.
The implant masquerades as a benign extension called Smart Bookmarks (version 1.3.0) and is not available on the Chrome Web Store; it is installed via sideloading, group policy force-install (ExtensionInstallForcelist / ExtensionSettings), or Chromium Secure Preferences manipulation. The main agent runs as an MV3 service worker backed by a content script (content.js) injected into every active web page, and requests broad permissions: cookies, tabs, history, downloads, bookmarks, scripting, proxy settings, native messaging, and all HTTP/HTTPS origins. Browser-resident capabilities run locally within the extension (full-page / viewport screenshots via chrome.tabs.captureVisibleTab, clipboard content, JavaScript injection, history and bookmark harvesting, active-tab metadata, local/session storage and DOM snapshot capture, form-input capture including password-like web fields). The service worker beacons to the C2 every 30 seconds over unencrypted HTTP, polling /api/commands for new tasks, registering via /api/register, posting results to /api/agents/<id>/task_result, and auto-collecting cookies, history, tabs, URL, IP, locale, and time zone to /api/exfil. Extension updates are delivered through /api/extension_update/ and /api/extension_crx/ endpoints, effectively giving the operator in-place payload refresh.
For OS-level operations the extension bridges out of the browser sandbox through Chrome's Native Messaging API to nm_host.exe, registered as com.peep.lab under the Chrome/Edge NativeMessagingHosts registry keys. The host runs in the compromised user's security context (no inherent privilege escalation) and supports shell command execution, file operations (list directories, read/write files, search for sensitive documents, create folders, rename, compute hashes, delete paths), process enumeration, and service enumeration. Credential impact is achieved primarily by stealing active session cookies, giving access to authenticated web accounts without passwords or MFA, and by capturing password-like form fields, rather than by decrypting Chrome's stored password database.
Persistence is multi-layered: (1) the installer forges Chromium's Secure Preferences integrity values, including per-entry HMACs and the top-level HMAC-SHA256 super_mac, so the modified extension settings appear legitimate to Chrome on next launch; (2) enterprise force-install/extension-settings group policies are abused; (3) Developer Mode is enabled to sideload arbitrary extensions (install_silent.ps1) and force_enable.ps1 strips the extension from Preferences' external_uninstalls, stages the CRX under %LOCALAPPDATA%\PEEP\crx, re-registers via the HKCU Extensions key and an External Extensions JSON manifest, then restarts the browser; (4) a ScriptCache fallback preserves the compiled malicious MV3 service worker so it reloads after browser restarts while only benign source files remain visible to manual review. Because the operational logic runs inside the signed browser process, the toolkit evades detection pipelines that key on new or unsigned binaries. A Python variant, patch_secure_prefs_linux.py, indicates the operator is adapting the Secure Preferences injection for Linux Chrome/Edge profiles. SOCRadar additionally noted references in the tooling to an 'Authorized CTF' use case, a framing commonly used to lower the safety guardrails of AI coding assistants during development. The nm_host.exe PE TimeDateStamp of July 2022 stems from the base pkg Node image used to build it, not the actual build date.
The activity is currently unattributed, though Chinese-language artifacts embedded in the source code point to a Chinese-speaking threat actor. The toolkit shares lineage with the GlassWorm supply-chain campaign (November 2025), which weaponized a fork of the same RedExt framework with near-identical Secure Preferences / super_mac HMAC injection tradecraft. BeaconBeagle correlation lookups for the C2 IP (206.237.30.232) and domain (xfjcc.fun) returned no registered C2-framework signatures, indicating the malware's Flask/SQLite panel is outside the tracked C2 frameworks catalog. From a defense perspective, PEEP is best understood as an endpoint-and-identity incident in one: detection should focus on extension inventory review (the two extension IDs), native-messaging host registrations, ~30-second HTTP beaconing to the known C2, PowerShell modifying Chromium preference files or external extension manifests, and remediation must remove the extension, the native-messaging host, registry entries, and staged CRX artifacts before rotating sessions and credentials.
MITRE ATT&CK techniques used in TL-2026-2380
Collection
T1005 Data from Local System; T1113 Screen Capture; T1119 Automated Collection
Discovery
T1007 System Service Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1217 Browser Information Discovery
Defense Evasion
Credential Access
T1056 Input Capture; T1539 Steal Web Session Cookie
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
defense-impairment
Persistence
Affected products and versions in PEEP: Chromium Toolkit Turns Chrome and Edge Into
Remediation for PEEP: Chromium Toolkit Turns Chrome and Edge Into
Patches
- No vendor CVE or patch applies (post-compromise malware, not a browser vulnerability); keep Chrome/Edge updated to reduce the sandbox-escape surface
Immediate actions
- Block and alert on HTTP egress to 206.237.30.232, xfjcc.fun and subdomains (new, newadmin, newapi), including recurring ~30-second beacon cadence from browser processes
- Audit all Chrome/Edge extension inventories and remove 'Smart Bookmarks' (IDs ejkndncpkdcjcikfhiamcdehdoegilbj and bibjjhidpdmfcbkodddndmoejcloobdh)
- Delete the com.peep.lab native messaging host registration (NativeMessagingHosts keys for Chrome and Edge) and the nm_host.exe binary
- Remove the staged CRX at %LOCALAPPDATA%\PEEP\crx and the installer scripts (install_silent.ps1, patch_secure_prefs.ps1, force_enable.ps1, patch_secure_prefs_linux.py)
Workarounds
- Enforce ExtensionSettings / ExtensionInstallForcelist enterprise policies to allowlist trusted extension IDs and block unknown sideloads
- Restrict NativeMessagingHosts registration to managed paths via Chrome/Edge enterprise policy where the feature is not business-required
Longer-term hardening
- Treat any PEEP infection as both an endpoint and identity incident: revoke all browser sessions, rotate credentials, and reset MFA tokens for accounts accessed from the host
- Restrict extension installation to enterprise allow-lists; block Developer Mode and external sideloading via policy
- Deploy behavioral detection for Chromium Secure Preferences integrity changes, super_mac/script-cache alterations, and external extension manifest writes
- Route browser telemetry (extension inventory, native messaging host list, network egress) into an EDR/SIEM correlation for post-exploitation hunting
Timeline of PEEP: Chromium Toolkit Turns Chrome and Edge Into
- nm_host.exe PE header TimeDateStamp of July 2022 noted by SOCRadar; stems from the base pkg Node image used to build the binary and does not reflect the actual build date
- RedExt open-source browser-extension C2 framework (Manifest V3 extension + Flask/SQLite control panel, MIT license) published to GitHub by author 'Darkrain2009', explicitly marketed for authorized red-team operations
- GlassWorm supply-chain campaign reported (Aikido, Breakglass) weaponizing a fork of the RedExt framework with near-identical Secure Preferences / super_mac HMAC injection tradecraft; PEEP shares this lineage
- PEEP C2 infrastructure observed live by SOCRadar: unauthenticated /health endpoint on the port-5001 control panel exposed 34 agent entries, ~10 active sessions, and 507 stored data records (test entries indistinguishable from real infections)
- Exposed development repository observed on TCP 5002 (new.xfjcc.fun) containing source code, builds, logs, utilities, and the private key for the primary extension identity
- SOCRadar publishes its PEEP browser RAT analysis; The Hacker News, GBHackers, and related outlets disclose the toolkit; activity remains unattributed with Chinese-language artifacts in the source
Sources cited for PEEP: Chromium Toolkit Turns Chrome and Edge Into
- The Hacker News — PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
- SOCRadar — PEEP: RedExt-Derived Browser RAT Disguised as a Smart Bookmarks (original analysis)
- GBHackers — PEEP Chrome Extension Turns Chrome and Edge Into Full-Remote Backdoors
- The Daily Tech Feed — New Chrome Extension 'PEEP' Turns Browsers Into Remote Backdoors
- IT Security News — Hackers Can Use PEEP Chrome Extension to Steal Credentials and Execute Shell Commands
- RedExt — Browser extension C2 framework (Darkrain2009) on GitHub
- Aikido Security — GlassWorm RAT Delivered via Malicious Chrome Extension
- Breakglass Intelligence — GlassWorm Wave 3: The Supply Chain Worm Goes Cross-Platform (RedExt Agent / super_mac)
- Cisco Talos — A Data-Driven Look at How Adversaries Are Weaponizing AI ('Authorized CTF' guardrail bypass)
Detection coverage for TL-2026-2380
As of 2026-09-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2380 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.