TechLair

  • Home
  • contact
  • About
  • Privacy Policy

Google Removes Over 500 Malicious Chrome Extensions

Thursday, February 13, 2020 by Piyush Suthar | Comments

Home News Tech Google Removes Over 500 Malicious Chrome Extensions

Google removes 500 malicious chrome extensions

A grueling investigation conducted by security researcher Jamila Kaya and Cisco’s Duo Security team has exposed over 500 malicious Chrome browser extensions. Google has now removed the malicious extensions from the Chrome Web Store.

These extensions ran malicious ads and uploaded private browsing data to servers without user consent. The researchers found that the malicious actors had been operating for at least two years and affected about 1.7 million users.

Kaya made use of Duo’s free automated Chrome extension security assessment tool CRXcavator for the initial findings. The researcher later collaborated with other researchers at Duo for finding more evidence.

“The Chrome extension creators had specifically made extensions that obfuscated the underlying advertising functionality from users,” wrote the researchers in a blog post. “This was done in order to connect the browser clients to a command and control architecture, exfiltrate private browsing data without the user’s knowledge, expose the user to risk of exploit through advertising streams, and attempt to evade the Chrome Web Store’s fraud detection mechanisms.”

For those wondering how these attackers managed to snoop on your browsing data, they relied primarily on plugins that’d redirected users to malicious websites. The researchers point out that the plugins had the same name as the harmful website.

For instance, the researchers found similar source code on two plugins namely Mapstrek and Arcadeyum among others. The malicious websites linked to the plugins were Mapstrek<dot>com and Arcadeyum<dot>com. These websites were hosted on AWS.

To stay safe from similar malicious extensions, the researchers recommend keeping track and regularly checking up on the extensions installed on your browser and removing the suspicious ones, if any.


Authored by Piyush Suthar
Pro Blogger


Follow me on Twitter, Facebook, Google+, YouTube.

Load comments
  • Newer Post
  • Home
  • Older Post
  • techlair
    Over 1,500+ Readers

    Get fresh content from TechLair

    brand222 facebook brand2 envelope-o

    BEST OF TechLair

    Yet another massive Facebook fail: Quiz app leaked data on ~120M users for years
    Samsung Galaxy Tab S4 with Dex and S Pen support launched at Rs 57,900
    Google Pixel 3 Official Launch Event Set For October 9
    Honor 9N India launch: When, where and how to watch the unveiling live


    Copyright © 2019 TechLair. All rights reserved.
    Privacy Policy • DMCA • Contact