9 ms·
Chrome extensions spying on users' browsing data
- hackinthebochs 8mo agoLoad extensions in developer mode so they can't silently install malware on you
- mentalgear 8mo agoBrowser extensions have much looser security than you would think: any extension, even if it just claims to change a style of a website, can see your input type=password fields - it's ludicrous that access to those does not need its own permission !
- sebzim4500 8mo agoIt's hard to see how you would implement that, any script run within the context of the page needs access to these fields for backwards compatibility reasons, so the context script of the extension would just need to find a way of running code in the context of the page to exfiltrate the data. It could do this by adding script tags, etc.
- throwaway0665 8mo agoBrowsers break backwards compatibility for security all the time. Most recently Chrome made accessing devices on a local network require a permission. They completely changed the behavior of cookies. They break loads of things for cross origin isolation.
- sebzim4500 8mo agoSure, but this would break a significant portion of sign in UIs.
- drdec 8mo agoEven scripts within the page itself cannot read the value of password input fields. This is less of an issue than you are presenting it as.
- Valodim 8mo ago...uhh, yes they can? Are you talking about input type=password fields, i.e. the ones 99% of passwords are entered in?
- matheusmoreira 8mo agoAnd the ones that are not will probably get bought out at some point and become malware as well. The only extension I trust enough to install on any browser is uBlock Origin.
- mcjiggerlog 8mo agoI have published an extension [1] that has 100k+ users and I've probably received hundreds of emails over the years asking me to sell out in one way or another. It's honestly relentless. For that reason I also only trust uBlock Origin, Bitwarden and my own extensions. I'd also note that all this spam is via the public email address you're forced to add to your extension listing by Google. I don't think I've ever had a single legitimate email sent to it. So yeh, thanks Google. [1] https://chromewebstore.google.com/detail/old-reddit-redirect/dneaehbmnbhcippjikoajpoabadpodje https://chromewebstore.google.com/detail/old-reddit-redirect...
- Hard_Space 8mo agoJust to say thanks for this extension, and keeping Reddit usable (at least for me).
- rat9988 8mo agoJust curious how much does it sell? It gives an idea about how much my personal data is worth
- mcjiggerlog 8mo agoI was just having a quick search and the only email I can find that offered a price range up front was for $0.1-0.4 per user, and that was from 2023. So I assume up to a dollar per user these days?
- xnorswap 8mo agoI imagine it must be very tempting to take that bag while old reddit is still usable. Thank you for not doing so.
- cebert 8mo agoHopefully people will start learning that you want to install as few browser extensions as possible.
- probably_wrong 8mo agoMy honest reaction to your comment is "What? No!". I want to block ads, block trackers, auto-deny tracking, download videos, customize websites, keep videos playing in the background, change all instances of "car" to "cat" [1], and a whole bunch of weird stuff that probably shouldn't be included in the browser by default. Just because the browser extension system is broken it doesn't mean that extensions themselves are a problem - if anything, I wish people would install more extensions, not less. [1] https://xkcd.com/1288/ https://xkcd.com/1288/
- mrweasel 8mo agoIn principle I agree with you, there is just so much crap online that it's tempting to just add this one more extension to fix something. Looking at my own installed extensions, I have a password manager, Privacy Badger and Firefox Multi-Account Containers, which I suppose is the three I really need. Then I have one that puts the RSS icon back in the address bar, because Mozilla feels that RSS is less important than having the address bar show me special dates, and two that removes very specific things: One for cookie popups and one for removing sign in with Google. The only one of these I feel should actually be a plugin is my password manager. Privacy management (including cookies), RSS and containers could just be baked into Firefox. All of those seems more relevant to me than AI. Maybe adding a GreaseMonkey lite could fix the rest of my problem, using code I write and control.
- notpushkin 8mo ago> one for removing sign in with Google You could use an adblocker rule instead: ||accounts.google.com/gsi/client$script (I’m not sure if it’s possible to do that with Privacy Badger though)
- ghostwords 8mo ago
- Pacers31Colts18 8mo agoI think the industry needs to rethink extensions in general. VSCode and browser extensions seem to have very little thorough review or thought into them. A lot of enterprises aren't managing them properly.
- drdec 8mo agoAbsolutely. I have not installed useful browser extensions because Mozilla isn't the maintainer. E.g. the Google container.
- kgwxd 8mo agoYo dawg...
- wormpilled 8mo agoI heard you wanted spyware in your spyware
- singularfutur 8mo agoThis is why I only run open source extensions that I can actually audit. uBlock Origin, SponsorBlock, the kind of tools where the code is available and the developer isn't anonymous. The Chrome Web Store is basically unregulated and Google doesn't care as long as they get their cut. Open source at least gives you a chance to see what you're installing before it starts exfiltrating your data to some server in a country you've never heard of.
- deleted 8mo ago[deleted]
- randunel 8mo agoHow do you check that the open sourced code is the same one that you are installing from the extension repository and actually running?
- fn-mote 8mo agoThis kind of nihilistic comment doesn’t do anything for me. There’s always a possibility of problems along the chain. You are reducing your risk not eliminating it.
- chrisjj 8mo ago> This kind of nihilistic comment doesn’t do anything for me. Got to say, mischaracterising a neutral question as a nihilistic comment doesn't do anything for me.
- endsandmeans 8mo agoI agree but let me play the devil's advocate. I'll channel Stallman: Same argument can be applied to all closed source software. In the end its about who you trust and who needs to be verified and that is relative, subjective, and contextual... always. So unless you can read the source code and compile yourself on a system you built on an OS you also built from source on a machine built before server management backdoors were built into every server... you are putting your trust somewhere and you cannot really validate it beyond wider public percetptions.
- PurpleRamen 8mo agoI don't really understand the complaint here. It seems for most of those extensions have it in their literal purpose to send the active URL and get additional information back, for doing something locally with it. And why does this site has no scrollbar?? WTF, is Webdsign finally that broken?
- moebrowne 8mo ago> And why does this site has no scrollbar Seems someone decided it was a good idea to make the scrollbar tiny and basically the same colour as the background: scrollbar-width: thin; scrollbar-color: rgb(219,219,219) rgb(255,255,255);
- PurpleRamen 8mo agoOh, thanks! It's working when you just hit the right pixel somewhere around the left border.
- qcontinuum1 8mo agoWe beg to differ. Consider for example "BlockSite Block Websites and Stay Focused" why would you need to send browsing data to remote server if your job is only to block selected domains?
- PurpleRamen 8mo agoIf you look at the request made, then it seems to check the category of the site, for whatever reason. I don't know that extensions, so I don't know if this is a legit use, sloppy use or harmful. I'm also not saying they found nothing at all. But looking through what they found, they seem to have not even thought much about whether those cases are legit and in the excepted and necessary realm of actions the add-on is supposed to do, or if it's really harmful behaviour. I also don't see anything about how often the request was made. Was it on every url-change, or just once/occasionally? This whole article is a bit too superficial for me.
- 8mo ago
- PlatoIsADisease 8mo agoMy initial solution was: >Before installing, make each user click a checkbox what access the extension has However, as I've seen on android, updates do happen, and you are not asked if new permissions are granted. (Maybe they do ask, but this is after an update automatically is taken place, new code is installed) Here are the two solutions I have, neither are perfect: >Do not let updates automatically happen for security reasons. This prevents a change in an App becoming malware, but leaves the app open to Pegasus-like exploits. >Let updates automatically happen, but leaves you open to remote, unapproved installs.
- PaperBanana 8mo agoIt's interesting to see this surface again. As someone currently looking into building extensions, the permission granularity has always felt like a double-edged sword. Even with Manifest V3 limiting some capabilities, the 'read and change all your data on the websites you visit' permission is still necessary for many legitimate tools, but it requires so much trust from the user. I wonder if a more granular, per-domain permission model (like mobile apps) would be feasible for the Chrome team to implement without breaking UX.
- endsandmeans 8mo agoMost of them jump out as immediately dodgy -- except Stylsh. That is the only one I've ever used on the list but it's been several years.
- Cyuonut 8mo agoStylish was sold in 2016, and has had spyware from at least 2018 on.
- fusslo 8mo ago"zoom", "LibreOffice Editor", "Enhanced Image Viewer", "Video Downloader PLUS" I guess I shouldnt be surprised on how many use "LibreOffice" or other legit company names to lend legitimacy to themselves. I'm wondering if companies like Zoom don't audit the extension store for copyright claims I for sure used to use Video Downloader PLUS when I still used chrome (and before youtube-dl)
- insin 8mo agoHN story about what Stylish was up to 7 and a bit years ago: https://news.ycombinator.com/item?id=17447816 https://news.ycombinator.com/item?id=17447816 I'd assumed most people would have jumped ship to Stylus [1] after that, but most people probably never heard anything about what Stylish was/is doing. [1] https://chromewebstore.google.com/detail/stylus/clngdbkpkpeebahjckkjfobafhncgmne https://chromewebstore.google.com/detail/stylus/clngdbkpkpee...
- notenlish 8mo agoI like stylus, it doesn't have an intuitive ui though. Wish they'd improve it.
- deanc 8mo agoOver 15 years ago now, I had a popular chrome extension that did a very specific thing. I sold it for a few thousand bucks and moved on. It seemed a bit strange at the time, and I was very cautious in the sale, but sold it and moved on. It's abundantly obvious to me now that bad actors are purchasing legitimate chrome extensions to add this functionality and earn money off the user's data (or even worse). I have seen multiple reports of this pattern.
- RupertSalt 8mo agoIt is a classic supply-chain attack. The same modality is used by gamers to sell off their high-level characters, and social media accounts do "switcheroos" on posts, Pages, and Groups all the time. You know, a lot of consumer cybersecurity focuses on malware, browser security, LAN services, but I propose that the new frontier of breaches involves browser extensions, "cloud integrations", and "app access" granted from accounts. If I gave permission for Joe Random Developer's app to read, write, and delete everything in Gmail and Google Drive, that just set me up for ransomware or worse. Without a trace on any local OS. A virus scanner will never catch such attacks. The "Security Checkup" processes are slow and arduous. I often find myself laboriously revoking access and signing out obsolete sessions, one by one by one. There has got to be a better way.
- dalmo3 8mo agoPardon the ignorance but what's being exploited by someone buying a video game character?
- deleted 8mo ago[deleted]
- elashri 8mo agoI think he was just saying that it is similar business to that. Just drawing comparison that there are a market like selling video games accounts. Also usually people who cheats in games will buy high level accounts because they will be banned much faster if they start playing with new accounts for cheats. This happens in some of the games I play all the time.
- l72 8mo agoThe fact that most of these are capturing query parameters: "u": "https://www.google.com/search?q=target", indicates that are capturing tons of authentication tokens. So this goes way beyond just spying on your browser history.
- cess11 8mo agoIf a service is sending auth tokens as URL parameters, stop using it. Those are always public.
- dangets 8mo agoI don't disagree with the advice (especially for long lived tokens), but query parameters are encrypted during transit with https. You still need to worry about server access logs, browser history, etc that might expose the full request url.
- karel-3d 8mo agohuh? https encrypts URL parameters?
- lapcat 8mo ago> We built an automated scanning pipeline that runs Chrome inside a Docker container, routes all traffic through a man‑in‑the‑middle (MITM) proxy, and watches for outbound requests that correlate with the length of the URLs we feed it. The biggest problem here is that "We" does not refer to Google itself, who are supposed to be policing their own Chrome Web Store. One of the most profitable corporations in world history is totally negligent.
- GuestFAUniverse 8mo agoAnd why didn't one of the wealthiest companies of the world capture this themselves? Considering the barriers they build to prevent adblockers, that doesn't shine a good light on them.
- nanobuilds 8mo agoThe browsing data itself is only half the problem. Even if you remove the spying extension, the profile it helped build persists and keeps shaping what you see as it gets sold and changes hands. We focus a lot on blocking data collection and spyware.. but not enough about what happens after the data is already collected/stolen and baked into your algorithmic identity. So much of our data is already out there.
- Grom_PE 8mo agoIt seems crazy to me that the offered way to install an extension on Chrome is to click a button on a privileged website, and then the installed extension autoupdates without an option to turn it off. I hate the idea of installing stuff without an ability to look at what's inside first, so what I did was patch Chromium binary, replacing all strings "chromewebstore.google.com" with something else, so I can inject custom JS into that website and turn "Install" button into "Download CRX" button. After downloading, I can unpack the .crx file and look at the code, then install via "Load unpacked" and it never updates automatically. This way I'm sure only the code I've looked at gets executed.
- captn3m0 8mo agoIf someone would like to replicate, a good approach would be to reduce the cost by removing a full-chromium engine. I doubt these extensions are trying to do environment detection and won’t run under (for eg) JSDOM+Bun with a Chrome API shim.
- kwar13 8mo agoThe code is usually minified and heavily obfuscated but you CAN view the source code for any extension: https://kaveh.page/snippets/chrome-extensions-source-code https://kaveh.page/snippets/chrome-extensions-source-code Even a tiny extension like this one I wrote with 2k users gets buyout offers all the time to turn it into malware: https://chromewebstore.google.com/detail/one-click-image-saver/ajpjioafnelcifjpgeekhbcjpphhfmgg https://chromewebstore.google.com/detail/one-click-image-sav...
- bennydog224 8mo agoIt’s obvious CWS has given up on oversight of these extensions. It’s a minefield.
- croes 8mo agoJust create an AI service and users will voluntarily send you all their data. No need for such complicated attacks /s
- bittercucumber 8mo agoOnly 37M? I'd have guessed a higher number than that.
- qcontinuum1 8mo agoWe were hoping to see that as well. There might be v2 of this research ;)
- georgehill 8mo agoAt this point, someone should make a site to check whether installed extensions are malicious or not.
- Chris2048 8mo agoWhy not do the opposite - a whitelist of extensions that don't appear malicious.
- burnt-resistor 8mo agoYou've just reinvented curation, but giving Google a pass for not them doing it themselves and shifting the work onto others. Multiple regulators should sue Google for putting users at risk by failing to protect users from malicious code before publishing Chrome extensions and Android apps.
- Chris2048 8mo agoA blacklist is also curation isn't it? Suing google is also 'work'.
- baggachipz 8mo agoAnd then an extension to alert you to bad extensions.
- james-bcn 8mo agoGreat idea! Someone please do this.
- Imustaskforhelp 8mo agoSo this would require a list of decided malicious extensions or not and someone can go ahead and check through that. To find the list of decided malicious extensions, I can imagine that a github repository where people can create issues about the lack of safety (like imagine some github repo where this case could've also been uploaded) and people could discuss and then a .txt/json file could be there in the repo which gets updated every time an extension is confirmed to be malicious. Thoughts? Edit: (To take initiative?) I have created a git repo with this https://github.com/SerJaimeLannister/unsafe-extensions-list https://github.com/SerJaimeLannister/unsafe-extensions-list but I would need some bootstrap list of malicious extensions. So I know nothing about this field and the only extension I can add is this one maybe but maybe someone can fork this idea (who is more knowledgable within the extension community space) or perhaps they can add entries into it. Edit 2: Looks like qcontinuum actually have a github repo and I hadn't read the article while I had written the comment but its not 1 extension but rather 287 extensions and they have mentioned all in their git repo https://github.com/qcontinuum1/spying-extensions https://github.com/qcontinuum1/spying-extensions So they already have a good bootstrapped amount & I feel as if qcontinuum is interested they can maybe implement the idea?
- gnl 8mo agoCouple of quick thoughts on how to protect yourself from having a formerly trustworthy extension go rogue on you: - https://github.com/beaufortfrancois/extensions-update-notifier-chrome-extension https://github.com/beaufortfrancois/extensions-update-notifi... And then you can do whatever you feel is an appropriate amount of research whenever a particularly privileged extension gets updated (check for transfer of ownership, etc.) - brave://flags/#brave-extension-network-blocking You can then create custom rules to filter extension traffic under brave://settings/shields/filters e.g.: ! Obsidian Web *$domain=edoacekkjanmingkbkgjndndibhkegad @@||127.0.0.1^$domain=edoacekkjanmingkbkgjndndibhkegad - Clone the GitHub repo, do a security audit with Claude Code, build from source, update manually
- dotancohen 8mo ago> Clone the GitHub repo, do a security audit with Claude Code, build from source, update manually This is a great idea. Are there any deterministic tools to audit an extension codebase?
- gnl 8mo agoI don't know, but if there were, I wouldn't expect them to do anywhere near as good a job or – perhaps somewhat counterintuitively – be anywhere near as reliable. Static rules only go so far when it comes to this stuff. And assuming that you're starting from a trustworthy base, and Claude Code (or similar) can focus its attention on recent changes to the repo in particular, I imagine sneaking actual malware in there would be pretty hard without throwing up a bunch of red flags. See also: - [0-Days \ red.anthropic.com]( https://red.anthropic.com/2026/zero-days/ https://red.anthropic.com/2026/zero-days/ ) EDIT: The main challenge here is more likely to be the noise, as the LLM is more likely to flag too much than too little, so I'd recommend putting together a prompt that has it group whatever it finds by severity and likelihood of malicious intent. EDIT 2: Re Anthropic link above – worth pointing out that finding intentionally introduced malware when you have access to the source code and git history is a hell of a lot easier than finding a 0-day. The malware has to exfil data eventually or do ransomware stuff, good luck hiding that without raising the alarm, plus any attempt at aggressive obfuscation will raise the alarm on its own. I'm not saying it's impossible, I am saying that I think it's very very hard.
- nekusar 8mo agoYes, and? Chrome/Google/Alphabet is spying on 100% of their users. Quit using Alphabet stuff, and your exploitation factor goes down a LOT.
- ubermonkey 8mo agoI legit do not understand the Chrome hegemony.
- nkmnz 8mo agoIs there a way to use extensions from a private repository only, where I control the code and build pipeline?
- felishiagreen12 8mo ago[dead]
- rkagerer 8mo agoHere are 3 examples identified in their results. Play Store pages for all 3 list strong assurances about how the developer declares no data is being sold to third parties, or collected unrelated to the item's core functionality. Brave Web browser (runapps.org) https://chromewebstore.google.com/detail/mmfmakmndejojblgceefkpinojhiacfk https://chromewebstore.google.com/detail/mmfmakmndejojblgcee... Handbrake Video Converter (runapps.org) https://chromewebstore.google.com/detail/gmdmkobghhnhmipbpplibkgekdfaacjp https://chromewebstore.google.com/detail/gmdmkobghhnhmipbppl... JustParty: Watch Netflix with Friends (JustParty.io) https://chromewebstore.google.com/detail/nhhchicejoohhbnhjpaaoajhbbghhfgh https://chromewebstore.google.com/detail/nhhchicejoohhbnhjpa... My open question to Google is: What consequences will these developers face for lying to you and your users, and why should I have any faith at all in those declarations?
- baby 8mo agoI’ve always thought that it’s crazy how so many extensions can basically read the content of the webpages your browse. I’m wondering if the research should go further: find all extensions that have URLs backed in them or hashes (of domains?) then check what they do when you visit these URLs
- qcontinuum1 8mo agoWithout any doubt the research could continue on this. We had many opportunities to make the scan even wider and almost certainly we would uncover more extensions. The number of leaking extensions should not be taken as definite. There are resource constrains. Those extensions try to actively detect if you are in developer mode. Took us a while to avoid such measures and we are certain we missed many extensions due to for example usage of Docker container. Ideally you want to use env as close to the real one as possible. Without infrastructure this doesn't scale. The same goes for the code analysis you have proposed. There are already tools that do that (see Secure Annex). Often the extensions download remote code that is responsible for data exfiltration or the code is obfuscated multiple times. Ideally you want to run the extension in browser and inspect its code during execution.
- coldtea 8mo agoCan extensions: be scoped, meaning only allowed to read/access when you visit a particular domain whitelist (controlled by the user)? be forced (by the extension API) to have a clear non-obfuscated feed of whatever they send that the user can log and/or tap onto and watch at any time? If not, I wouldn't touch them with a 10000ft pole.
- notpushkin 8mo ago> be scoped Yes. Not usually user-controllable though. > be forced to have a clear non-obfuscated feed Kinda. You can usually open a devtools instance that shows whatever the extension is doing. But you can’t enforce it to not obfuscate the network requests though (you’d have to make extensions non-Turing complete). You could mitigate some of these issues by vetting the extensions harder before letting them into the stores. Mozilla requires all extensions to have a readable source code, for example.
- giarc 8mo agoMy daughter, in grade school, uses a Chromebook at school and access Google Classroom through Chrome. The school has very few restrictions on extensions and when I log into her account, Chrome is littered with extensions. They all innocuous (ex. change cursor into cat, pets play around on your screen etc). However, without fail, each time I log in and go to the extension page, Chrome notifies me that one or more of the extensions was removed due to malicious activity or whatever.
- Imustaskforhelp 8mo agoI don't think that your daughter might know if say any web cam might take photos and see what she's searching if the extensions are indeed malicious. I'd either go ahead and talk to her and remove extensions altogether and ask her to have a stock/only open source extensions (yes opensource also has supply issues but its infinitely more managable than this) or the second option being to maybe create them yourself . I don't know about how chrome works (I use firefox) but one thing that you can do is if the thing is simple for your daughter, then just vibe code it and use tampermonkey (heck even open source it) and then audit the code written by it yourself if you want better security concerns. Nowadays I really just end up creating my own extensions with tampermonkey before using any proprietory extension. With tampermonkey, the cycle actually feels really simple (click edit paste etc.) and even a single glance at code can show any security errors for basic stuff and its one of the few use cases of (AI?) in my opinion.
- ghtbircshotbe 8mo agoCapital One just offered me $45 to install a Firefox extension. I declined, though I'm sort of tempted to get paid for getting spied on which I assume is happening anyway. And who knows, maybe I could get a couple more bucks later in the class action. https://addons.mozilla.org/en-US/firefox/addon/wikibuy-for-firefox/ https://addons.mozilla.org/en-US/firefox/addon/wikibuy-for-f...
- soared 8mo agoTheir offers are very hard to claim - only eligible to be used in their store, only given after making a purchase in their store, among other random strings. I tried to claim the same offer but could never actually get it.
- ghtbircshotbe 8mo agoThat sounds right. I looked through the terms of the offer and it looked pretty onerous. I almost get the feeling they're trying to use my own hatred of the banks and desire to screw them out of $45 to trick me
- neya 8mo agoNobody is going to even do anything about SimilarWeb for pulling this off? My understanding from the article is that they're actively behind this. When I was the CTO in a previous role, SimilarWeb approached us. I read through the code snippet they gave us to inject onto our site. It was a sophisticated piece of borderline spyware that didn't care about anyone in the entire line of sight - including us. They not only were very persistent, they also had a fight with our management - for refusing to use their snippet. They wanted our data so bad (we had very high traffic at the time). All we wanted was decent analytics for reporting to senior management and Google had just fucked up with their GA4 migration practices. I switched them to Plausible.io and never looked back. It was the least I could do, we had to trade-off so many data points in comparison to GA, but still works flawlessly till date. Fuck SimilarWeb.
- chenmx 8mo ago[dead]
- hannob 8mo agoThat can't be true, right? I mean, Google broke Adblockers in Chrome to prevent this very issue. And it had absolutely nothing to do with Google's Ad business. So it's completely impossible that such malicious extensions still exist. (may contain sarcasm)
- jerrygoyal 8mo ago[flagged]
- ArcaneMoose 8mo agoExtensions have too many security risks for me. At this point I'd rather just vibe code my own extension than trust something with so much access and unpredictable ownership.
- molticrystal 8mo agoUsing the below page you can check your extensions, select all your extensions on chrome://extensions/ (everything on the page, it will filter it out IDs) and it will check if any IDs match. https://output.jsbin.com/gihukasezo/ https://output.jsbin.com/gihukasezo/ or https://jsfiddle.net/9kLsv3xm/latest/ https://jsfiddle.net/9kLsv3xm/latest/ or https://pastebin.com/Sa8RmzcE https://pastebin.com/Sa8RmzcE
- singularity2001 8mo agoThe whole browser is spying on you, so don't worry about extensions
- bittercynic 8mo agoIt is, but the particular ways Google will harm you are very different from how small/medium criminals will harm you.
- ravenstine 8mo agoThis is why I disable automatic updates. Not just for browser extensions but everything. This whole "you gotta update immediately or you're gonna get hacked" thing is a charade. If anything, if you update you'll be hacked at this point.
- leptons 8mo agoDamned if you do, damned if you don't.
- welanes 8mo agoMade a quick tool so you can check if your extensions are on the list: https://extensioncheck.val.run https://extensioncheck.val.run 1. Go to chrome://extensions and toggle Developer mode on (so IDs are visible) 2. Select all text on the page with your mouse and copy 3. Paste it into the tool It parses the IDs and warns you if any are among the 287 spyware extensions.
- the_gipsy 8mo agoRemember when google removed extension APIs so that things like uBlock origin stopped working in Chrome, in the name of "security"? Pepperidge farm remembers.
- herf 8mo agoYou know, LLMs could do automated code reviews for each update to avoid things like this. It would be much better than unexamined updates.
- heavenlyfather 8mo ago@qcontinuum1 appreciate this kind of research. saw your other comments and you mentioned that the team's engineering resources are scarce + saw that at the bottom of the github repo that there are links to BTC address. curious to know: 1- how large your team is? and how long this research took? it is very thorough and knowing such a detail might encourage others to participate in a joint effort in performing this kind of research 2- if this kind of research is your primary focus? 3- if there are other ways that financial support can be provided other than through xrp or btc? i tried to look up your profiles but wasn't able to find where you were all from, so wishing you well wherever you are in the world. :)
- qcontinuum1 8mo agoThank you. We are very glad to see the discussion that the report has sparked and and also glad to see the feedback on it. It means a lot to us. > 1- how large your team is? and how long this research took? it is very thorough and knowing such a detail might encourage others to participate in a joint effort in performing this kind of research The group is not very large and it took a few months of non-continuous work. > 2- if this kind of research is your primary focus? At the moment it is not very clear if we will do followup on this topic or not as explained in different comment. At the moment yes, the group is new. > 3- if there are other ways that financial support can be provided other than through xrp or btc? No, at the moment. We would like to remain anonymous, at least for now.
- revicon 8mo agoIf you're on a mac, you can list all the IDs of your installed browser extensions across all your profiles like this... find "$HOME/Library/Application Support/Google/Chrome" \ -type d -path "*/Extensions/*" -not -path "*/Extensions/*/*" \ -print 2>/dev/null | sed 's#.*/Extensions/##' | sort -u Compare to the list of bad extensions. I stuck a stripped down list here... https://www.sfbaylabs.org/files2/2026-02-11/chrome_extensions_exfiltrating_history.txt
- revicon 8mo agoHere's a one-shot script that does the compare for you, in case it's helpful... https://www.sfbaylabs.org/files2/2026-02-11/bad_browser_extension_check_osx.sh You can run it directly if you cut/paste this in your mac terminal... curl -fsSL https://www.sfbaylabs.org/files2/2026-02-11/bad_browser_extension_check_osx.sh | bash
- amalter 8mo agoIs there any irony in a thread on browser malware that includes a "please run this bash script blind"? Not that I don't trust you, but between now and when someone stumbles on this thread, your domain could expire and I could publish something crazy at that url.
- revicon 8mo agoThis is why I put the raw url to the script first in my comment. Downloading the script file, doing a chmod +x and then a ./script.sh to execute it is daunting for some. But I'll add a caveat to my original comment as well. edit: Looks like I can't edit my original comment anymore.
- nipperkinfeet 8mo agoStylus is a good alternative to Stylish. I keep my extensions to a minimum, and I turn off the ones I don't need until I need to use them. The only extensions I have turned on all the time are uBlock, Humble New Tab Page, and Stylus.
- adilblati3 8mo ago[dead]
- mickelsen 8mo agoI still use the Little Rat extension, it shows a little notification when an extension does a network request, and lets you see quickly what type and where. It can also block requests (doesn't seem to work all the time in Brave now, even with the flag on), activate and deactivate extensions: https://github.com/dnakov/little-rat https://github.com/dnakov/little-rat There's also this site that I've used from time to time to audit extensions quickly: https://chrome-stats.com/ https://chrome-stats.com/
- legitimate_key 8mo agoThe concerning pattern is that the data-collecting ones actively hide what they're doing — the Similarweb-linked extensions apparently obfuscate with Base64 or AES-256 before sending. Worth distinguishing from extensions that are genuinely client-side. A basic test: check the extension's manifest for network permissions (host_permissions). If it only requests the active tab and has no background network access, it physically cannot phone home. The inspection is 30 seconds in chrome://extensions. The more insidious problem is that users can't easily distinguish between "this extension processes data locally" and "this extension processes data locally and also sends it somewhere." Same UI, very different behavior.