Malware News Suspicious extensions with 4 million installs discovered in Chrome Web Store

nicolaasjan

Level 5
Thread author
Verified
Well-known
May 29, 2023
237
(Dutch article)

Translated:

Researchers have discovered dozens of suspicious browser extensions in the Chrome Web Store that have a combined installation count of four million. And that's striking because the extensions are "unlisted," meaning they can't be found through the Chrome Web Store or search engines. The only way to get to these extensions is to know their URL.

In total, there are 35 extensions that ask for various permissions that allow them to access web traffic on all visited URLs, access stored cookies, manage browser tabs and execute scripts. According to a researcher from Secure Annex, it is clear that the extensions collect browser information, including visited websites.

The extensions claim to offer security and search-related features. Given the permissions and design of the extensions, the researcher has reported them to Google, so that the tech company can remove them from the Chrome Web Store. In addition, users of the extensions are urged to remove them from their systems.
 
Last edited:

harlan4096

Super Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
9,072
Application name: firefox.exe
Application path: C:\Program Files\Mozilla Firefox
Component: Web Threat Protection
Result description: Detected
Type: Trojan
Name: HEUR:Trojan.Script.Generic
Precision: Heuristic analysis
Threat level: High
Object type: File
Object name: index.BDU7bgiq.js
Object path: https:// secureannex . com/assets
SHA256 of an object: B0565EF711B5D80B9E742D2300025A755BE6BF0751C15E10C43A3C6FAE1316C2
MD5 of an object: A01DC79BEB90C8F4D4B3E77EAF367A76
Reason: Expert analysis
Databases release date: Today, 11/04/2025 11:40:00

🤔
 
Last edited:

TairikuOkami

Level 38
Verified
Top Poster
Content Creator
Well-known
May 13, 2017
2,760
I use only one Edge extension, but I have recently added extensions cleanup, just in case something sneaks in.
Code:
del "%LocalAppData%\Microsoft\Edge\User Data\Default\Extension Cookies" /s /f /q
del "%LocalAppData%\Microsoft\Edge\User Data\Default\ExtensionActivityComp" /s /f /q
del "%LocalAppData%\Microsoft\Edge\User Data\Default\ExtensionActivityComp-journal" /s /f /q
del "%LocalAppData%\Microsoft\Edge\User Data\Default\ExtensionActivityEdge" /s /f /q
del "%LocalAppData%\Microsoft\Edge\User Data\Default\ExtensionActivityEdge-journal" /s /f /q
rd "%LocalAppData%\Microsoft\Edge\User Data\Default\Extension Rules" /s /q
rd "%LocalAppData%\Microsoft\Edge\User Data\Default\Extension Scripts" /s /q
rd "%LocalAppData%\Microsoft\Edge\User Data\Default\Extension State" /s /q
rd "%LocalAppData%\Microsoft\Edge\User Data\Default\Local Extension Settings" /s /q
rd "%LocalAppData%\Microsoft\Edge\User Data\Default\Managed Extension Settings" /s /q
rd "%LocalAppData%\Microsoft\Edge\User Data\Default\Sync Extension Settings" /s /q
 

nicolaasjan

Level 5
Thread author
Verified
Well-known
May 29, 2023
237
Same. I was about to post this.
"Reason: Expert analysis" This part is what concerns me.
I can assure you that I didn't link to a malicious website on purpose.

Anyone here who can read this 512KB script? :unsure:

I see on VirusTotal that it was Kaspersky that marked it as HEUR:Trojan.Script.Generic
And Rising marked it as Stealer.Agent/JS!1.12736 (CLASSIC).
 
Last edited:

SeriousHoax

Level 51
Verified
Top Poster
Well-known
Mar 16, 2019
4,009
Weirdly if I load the site, it does not even connect to the domain. This asset was not loaded on my device on the site :unsure:
"Reason: Expert analysis" This part is what concerns me.
This basically means that the heuristic signature that detected this file was created a human malware analyst, not automated signature or ML based detection. It doesn't necessarily mean that an analyst analyzed this exact file and created the detection. But some suspicious code in that file triggered the detection.
No detection from ESET on this file.
 

harlan4096

Super Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
9,072
1744399397757.png
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top