McAfee threat analysts have identified five Google Chrome extensions that steal data related to users' browsing activity . Collectively, the extensions have been downloaded more than 1.4 million times.

The purpose of the malicious extensions is to track when users visit e-commerce sites. They then insert code into the sites that modifies the cookies on the site to make it appear as if they came from a referrer link. Thus, the creators of the extensions receive an affiliate payment for any purchases made in online stores.
See also: START: Russian streaming platform suffers data breach
The five malicious extensions discovered by McAfee researchers are as follows:
- Netflix Party (mmnbenehknklpbendgmgngeaignppnbe) – 800,000 downloads
- Netflix Party 2 (flijfnhifgdcbhglkneplegafminjnhn) – 300,000 downloads
- Full Page Screenshot Capture – Screenshotting (pojgkmkfincpdkdgjepkmdekcahmckjp) – 200,000 downloads
- FlipShope – Price Tracker Extension (adikhbfjdbjkhelbdnffogkobkekkkej) – 80,000 downloads
- AutoBuy Flash Sales (gbnahglfafmhaehbdmjedfhdmimjcbed) – 20,000 downloads

These extensions do what they promise, making it harder for victims to notice their malicious activity. Although their use does not directly affect users, they pose a serious risk.
Therefore, if you are using any of the above extensions, you should remove them from your browser immediately.
How do malicious extensions work?
According to McAfee researchers, all five Google Chrome extensions behave similarly. The web app manifest (the “manifest.json” file), which dictates how the extension should behave on the system, loads a multi-function script (B0.js) that sends browsing data to a domain controlled by the attackers (“langhort[.] com”).
Data is delivered via POST requests whenever the user visits a new URL. The information that reaches the fraudster includes the URL in base64 format, the user ID, the device (country, city, zip code), and an encoded referring URL.
See also: Phishing: Hackers hide malware in image of James Webb
If the website a user visited matches any entry in a list of websites for which the extension author has an active affiliation, the server responds to B0.js with one of two possible actions.
- The first, “Result['c'] – passf_url”, instructs the script to insert the provided URL (referral link) as an iframe into the website the user visited.
- The second, “Result['e'] setCookie“, instructs B0.js to modify the cookie or replace it with the provided one, if the extension has been granted the relevant permissions to perform this action.
McAfee also published a video to show how URL and cookie modifications are made in real time:
To avoid detection and confuse researchers or even more cautious users, some of the malicious extensions start sending user browsing activity at least 15 days after initial installation.
See also: Interworks cloud: Cyberattack on cloud provider? [updated]
At this time, the “Full Page Screenshot Capture – Screenshotting” and “FlipShope – Price Tracker Extension” extensions are still available in the Chrome Web Store.
The two Netflix Party extensions have been removed from the store, but this does not delete them from browsers, so users will have to uninstall them themselves to stop being tracked.
More details can be found in McAfee's report. This report highlights the risk of installing extensions, even those that have many users.
McAfee advises its customers to be cautious when installing Google Chrome extensions and to pay attention to the permissions they request. Permissions will be displayed by Chrome before the extension is installed. Customers should take additional steps to verify authenticity if the extension requests permissions that allow it to run on every website they visit.
Source: www.bleepingcomputer.com
