GemStone malicious extension backdoor (background.js, kc_state)

Detects the installation or presence of the GemStone browser extension backdoor. The detection logic identifies the malicious extension by flagging specific service worker file names ('background.js') located in browser extension directories, or by detecting browser extension events associated with unique indicators found in the 'AdditionalFields' metadata, specifically looking for keys such as 'kc_state', 'portal_sync_config', or a 'background.js' file reference.