• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Malicious Chrome and Edge Extensions Affect Millions of Users

You are here: Home / General Cyber Security News / Malicious Chrome and Edge Extensions Affect Millions of Users
December 17, 2020

3 million Google Chrome and Microsoft Edge end users could be at risk of data theft and phishing right after scientists identified malware hidden in multiple browser extensions.

At least 28 3rd-party extensions were being uncovered to have destructive JavaScript which could download supplemental malware, in accordance to Avast. The extensions by themselves are predominantly created to assistance end users down load movie from some of the world’s most well-liked web-sites which includes Fb, Vimeo, Instagram and YouTube.

Avast claimed the conclusion target for all those guiding the scheme could be to monetize traffic by forcing people to take a look at 3rd-party internet sites, which they then get paid for, while people could also conclusion up on phishing internet sites.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“Anytime a user clicks on a backlink, the extensions send out details about the click on to the attacker’s control server, which can optionally deliver a command to redirect the sufferer from the genuine url focus on to a new hijacked URL before afterwards redirecting them to the actual web page they desired to check out,” the Prague-based mostly security vendor stated.

“User privacy is compromised by this process considering the fact that a log of all clicks is currently being sent to these 3rd-party middleman web-sites. The actors also exfiltrate and obtain the users’ birth dates, email addresses, and machine info, such as very first indicator-in time, very last login time, title of the system, working process, made use of browser and its version, even IP addresses (which could be utilised to discover the approximate geographical location history of the person).”

At existing it is unclear whether or not the extensions have been crafted intentionally with malware hid inside, or if malicious actors waited for them to become popular and then pushed a malware-laden update.

“It could also be that the creator bought the unique extensions to anyone else immediately after creating them, and then the buyer introduced the malware afterwards,” mentioned Jan Rubín, malware researcher at Avast.

“The extensions’ backdoors are well concealed and the extensions only start to exhibit malicious actions times immediately after set up, which designed it really hard for any security program to find out.”

While Avast first detected the danger in November, the vendor admitted it could have been energetic for decades.

Curiously, if an infected person performs a web search on one particular of the malicious domains, the malware in query will stop action on their equipment, in buy to disguise from look at. Avast claimed it will do the exact same if it detects that the person could be a web developer, although it’s unclear how.

As the extensions are at this time nonetheless offered, Avast advised users disable or uninstall them.


Some pieces of this write-up are sourced from:
www.infosecurity-journal.com

Previous Post: «How To Use Password Length To Set Best Password Expiration How to Use Password Length to Set Best Password Expiration Policy
Next Post: Malware found on popular Facebook, Instagram and Vimeo browser extensions Malware Found On Popular Facebook, Instagram And Vimeo Browser Extensions»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.