What's new

Google Chrome extensions with 500,000 downloads found to be malicious

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

D

Dan Goodin

Guest
chrome-extension-800x488.jpg

Enlarge (credit: ICEBRG)


Researchers have uncovered four malicious extensions with more than 500,000 combined downloads from the Google Chrome Web Store, a finding that highlights a key weakness in what's widely considered to be the Internet's most secure browser. Google has since removed the extensions.

Researchers from security firm ICEBRG stumbled on the find after detecting a suspicious spike in outbound network traffic coming from a customer workstation. They soon discovered it was generated by a Chrome extension called HTTP Request Header as it used the infected machine to surreptitiously visit advertising-related Web links. The researchers later discovered three other Chrome extensions—Nyoogle, Stickies, and Lite Bookmarks—that did much the same thing. ICEBRG suspects the extensions were part of a click-fraud scam that generated revenue from per-click rewards. But the researchers warned that the malicious add-ons could just as easily have been used to spy on the people or organizations who installed them.

"In this case, the inherent trust of third-party Google extensions, and accepted risk of user control over these extensions, allowed an expansive fraud campaign to succeed," ICEBRG researchers wrote in a report published Friday. "In the hands of a sophisticated threat actor, the same tool and technique could have enabled a beachhead into target networks."


Read 3 remaining paragraphs | Comments

Continue reading...
 
This is serious, 500000 downloads of this nasty extensions is a big threat. It took them so long to find anything suspicious after 500000 people had already suffer.
 
Just goes to show that Chrome is the replacement of MSIE these days...
 
Just goes to show that Chrome is the replacement of MSIE these days...

Except this ain't drive-by installation like ActiveX used to be.

Not impressed however by Google not doing a better job at monitoring what gets published to their extension store.
 
Not impressed however by Google not doing a better job at monitoring what gets published to their extension store.

Better than Play Store on Android - challenge is that many ChromeBooks now have access to Android Apps, which makes it very important for Google to improve their overall application acceptance policies.

The upside for Chrome/Chromebooks is that it's a better managed platform from a security perspective, they can deploy fixes into Production/Stable versions fairly quickly unlike Android (generally speaking).
 

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!

Members online

Top