HomeinetEight hacked Chrome extensions serve malicious code

Eight hacked Chrome extensions serve malicious code

Six more Chrome extension developers have discovered that their accounts have been compromised over the past four months, according to new data revealed yesterday by Proofpoint security researcher Kafeine.Chrome

Earlier this month, we reported on the hijacking of yet another Chrome extension (Copyfish). As seen in all cases, the attackers used phishing emails to trick developers into giving them login credentials to their Chrome developer accounts.

Security researcher Kafeine identified six additional Chrome extensions that had been hijacked in the same way.

The list includes:

If you now add up the total installs from the eight extensions, you will see that the attackers managed to deliver their malicious code to around 4.8 million users.

On the other hand, Google is reportedly warning Chrome extension developers to be very wary of phishing attempts.

Google sent out a warning two weeks ago because in all of the above attacks, phishing was the first step in the process.

Security researcher Kafeine analyzed the malicious code he found in some of the extensions and discovered that it was designed to perform the following functions:

  • Wait at least ten minutes after installing-updating the extension
  • Retrieving a JavaScript file from a random DGA-generated domain
  • Collecting aggregate authentication data from the user's browser
  • Replacing ads with ads provided by the malicious user
  • Most ad replacements come from adult portals
  • Displaying a pop-up message notifying users of an error and redirecting to other websites, adding more traffic to them

The phishing attacks, according to the researcher, have been taking place since May 2017, and appear to be linked to the infrastructure used in another malicious Chrome extension, which was discovered in June 2016.

This indicates that the malicious users behind these attacks are very experienced in the inner workings of Chrome extensions and the Chrome Web Store and will likely continue their attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS