Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

Software Access

Software Access is a malicious Google Chrome extension identified by Socket as part of a coordinated campaign involving five malicious extensions targeting customers of Workday, NetSuite, and SAP SuccessFactors. Published under the name Software Access, it masqueraded as a productivity or access tool for enterprise HR/ERP platforms. Its core capability is theft of authentication cookies/tokens and session hijacking. Unlike the other related extensions, Software Access also supports bidirectional cookie injection: it can receive stolen cookies from attacker-controlled infrastructure at api.software-access[.]com, remove existing cookies for a target domain, and inject attacker-provided cookies into the browser using chrome.cookies.set(), enabling direct session relay and authenticated account takeover. The reported behavior can bypass MFA because valid session tokens are implanted directly rather than requiring credentials. Socket also reported anti-analysis functionality in Software Access through use of the DisableDevtool library to hinder browser code inspection. Across the broader campaign, the extensions shared similar API structures, monitored for the same list of 23 security-related Chrome extensions, and were assessed as likely operated by the same threat actor. The campaign collectively reached roughly 2,300 installs before removal from the Chrome Web Store. High-confidence associated indicators include the extension ID bmodapcihjhklpogdpblefpepjolaoij and the C2 domain/api endpoint software-access[.]com / api.software-access[.]com.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

scworldNews
Jan 20, 2026
Workday, NetSuite and SuccessFactors sessions targeted by malicious Chrome extensions | SC Media

Malicious Chrome extension that steals authentication cookies/tokens and supports direct session relay by injecting stolen tokens from its C2 into an attacker-controlled browser that also has the extension installed. Includes anti-analysis via DisableDevtool to hinder inspection.

Read more
cso onlineNews
Jan 20, 2026
Fünf Chrome-Erweiterungen, die Unternehmenssitzungen kapern | CSO Online

Bösartige Browser-Erweiterung, die Cookies/Session-Tokens stiehlt und diese anschließend per bidirektionaler Cookie-Injektion (u.a. via chrome.cookies.set()) in einen vom Angreifer kontrollierten Browser setzt, um ohne weitere Benutzerinteraktion eine authentifizierte Sitzung zu übernehmen (Session Hijacking).

Read more
security online infoNews
Jan 19, 2026
Fake Productivity Tools: 5 Malicious Chrome Extensions Hijack Enterprise Sessions

A malicious Chrome extension that performs bidirectional cookie injection: pulls attacker-provided session material from C2 and injects it into the victim browser to hijack sessions and bypass MFA without needing passwords.

Read more
the hacker newsNews
Jan 16, 2026
Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts

Malicious Chrome extension that both steals cookies and supports server-driven cookie injection (removing existing cookies and setting attacker-supplied cookies via chrome.cookies.set) to directly instantiate a victim session in the attacker’s browser; includes measures to hinder credential inspection.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.