PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

Executive Summary

Cybersecurity researchers revealed PEEP, a Chromium‑based post‑exploitation toolkit that masquerades as a bookmarks extension. After gaining administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s Secure Preferences. The tool enables host command execution from the compromised browsers.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-07T18:12:09+00:00 - Category: threat-intel

Original Description: Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

"You get peace of mind not by thinking about it or imagining it, but by quietening and relaxing the restless mind."

— Remez Sasson
Source: The Hacker News