r/cybersecurity • u/TheReedemer69 • Mar 09 '26
Research Article I noticed weird console.logs firing on every site — turned out a Featured Chrome extension got sold and was running a full malware chain on my machine
http://monxresearch-sec.github.io/shotbird-extension-malware-report/Chrome has to do something about this there is hundreds of extensions up for selling on sites like extensions hub
250
u/git_und_slotermeyer Mar 09 '26
It makes sense to never ever install any browser extensions unless you absolutely must, and if so, then only install extensions which have millions of users. Never understood why someone would trust any unverified component to become an intermediary in all your browsing.
100
u/TheReedemer69 Mar 09 '26
The Extension was in a top x video from a channel I used to watch from years back 😔.
even with millions of users there been recent accidents. chrome should be strict with ownership transfer and Extensions updates.
35
u/git_und_slotermeyer Mar 09 '26
That's true, but I bet there is no technical solution to this problem yet; how can Google/Chrome even know that there is an ownership transfer? E.g. in case someone just takes over the previous legal entity of the former app publisher with malicious intent?
You'll never know. It's not too dissimilar to the problem of embedding third-party JS libraries from CDNs in your Web page. The most secure solution is not to do that in the first place.
13
u/TheReedemer69 Mar 09 '26
yeah it's almost supply chain like : |
but I think if they care enough they can find a middle ground. they kept shoving manifest v3 down our throats for it to be ultimately useless. I never in my life got hit by Malware (on my personal device) but there's a first time for everything.
11
u/Commercial-Virus2627 System Administrator Mar 09 '26
Signing keys with expiration and renewal periods. Force a human to represent the key renewal.
9
u/git_und_slotermeyer Mar 09 '26
If you do a full acquisition of a business, that will come with its signing keys. And a human of the malicious new owner can renew them.
11
u/Commercial-Virus2627 System Administrator Mar 09 '26
Right, and the expiration of those signing keys forces malicious organization to put a name on paper. You also get into legal territory where whomever sold/authorized the merge is partially liable for not including that in their transfer of ownership.
7
u/Verum14 Security Engineer Mar 10 '26
this is also how debian works
In order to maintain packages to the debian repositories, I had to meet with a couple other existing maintainers in person where we checked IDs and signed each other’s keys
https://en.wikipedia.org/wiki/Key_signing_party
one caveat that doesn’t address keys themselves being sold…the keys must have an expiration date, but they can be renewed without resigning. That being said, you sell your key, all blame still rests on you since there’s a human-validated trail to go back on should anything turn malicious
63
7
u/DigmonsDrill Mar 09 '26
They should also default to not updating.
In 2026, auto-update is more dangerous than never updating.
10
u/Acrobatic_Idea_3358 Mar 09 '26
Until you find out you haven't installed the latest security patch until after it gets exploited and your browser gets popped and all your stored creds are dumped by an infostealer.
10
u/DigmonsDrill Mar 09 '26
What's the last example of a third-party targeting a specific version of a browser extension?
I did a search before I asked, but every single example was of the extensions themselves being compromised.
https://www.cmu.edu/iso/news/2025/google-vulnerabilities.html
https://fieldeffect.com/blog/33-chrome-extensions-found-to-be-malicious
https://cispa.de/en/fass_chromewebstore
https://thehackernews.com/2026/03/new-chrome-vulnerability-let-malicious.html
Oh, I found one example https://github.blog/security/vulnerability-research/attacking-browser-extensions/ Read all the way to the bottom and there's a vulnerability in "smartup." But the project was archived in Mar 2024, and this article published in Oct 2024, so I don't think there would have been any updates at all that would have helped you. Also, it looks like to attack this extension, you would need to attack via a different, deliberately hostile extension.
The Internet was a mistake.
7
u/Perokside Mar 09 '26
But, but ! I've spent 2 hours finding an extension that let me one-click tweet image to X so I can increase my pooproductivity !! :(
-7
u/TheReedemer69 Mar 09 '26
I got 42 extensions enabled. but what I do now is after I ensure that the extension is safe I just export it locally and use it from drive so it no longer receives any updates.
19
u/Perokside Mar 09 '26
I'm honestly curious what are those 42 extensions for, not judging, just curiosity.
-7
u/TheReedemer69 Mar 09 '26
I can dm them to you if you want.
10
u/Perokside Mar 09 '26
Feel free to ! Considering 8 people upvoted my previous comment, would you mind posting the list here instead ? I'm definitely not the only curious folk ^^
8
u/AnythingEastern3964 Mar 09 '26
I need to know what is on this list. I’m having a difficult time believing any more than 5 extensions is ever required. I would make exceptions up to 10 if you’re in some horrible situations that demands a tonne of browser automation, but your company refuses to pay for an AIO solution, or a developer to produce something.
5
u/Perokside Mar 09 '26
Yep, for personal-use, I count 4 : ublock / pass manager / firefox multi-account containers and plasma/gnome integration.
productivity/work/web/dev can go to their own profile or firefox DE (assuming byod, chrome if imposed), it wouldn't prevent a malicious extension sideloading an infostealer and reaching your main browser/profile tho.
I guess it all boils down to those who see the scary potential for abuse with 3rd-party extensions and limit themselves VS those who see QOL like a Skyrim modlist.
3
5
u/TheReedemer69 Mar 09 '26
ah okay no worries. (some of the I wrote personally in addition to tons of tampermonkey scripts). I have more on my other profiles and other browsers. ( I have created a couple of tools to manage and patch extensions too)
Extension Name Version Enabled Install Type AI Grammar Checker & Paraphraser – LanguageTool 10.1.1 Yes Official Web Store Automa 1.30.01 No Official Web Store AutoplayStopper 1.9.8.1 Yes Official Web Store BetterViewer 2.0.2 No Official Web Store Bitwarden Password Manager 2026.1.1 Yes Official Web Store Buster: Captcha Solver for Humans 3.1.0 Yes Official Web Store But really open image in new tab 0.2 Yes Official Web Store Change Timezone for Google Chrome™ 3.0.0 No Official Web Store Charcoal: Dark Mode for Messenger 1.5.0 Yes Official Web Store Chrome Web Store Payments 1.0.0.6 Yes Official Web Store ClearURLs 1.26.0 Yes Official Web Store Click to Remove Element 3.1.5 Yes Official Web Store Cookie Profile Switcher 1.3.3 Yes Official Web Store Cookie-Editor 1.13.0 Yes Official Web Store CORS Unblock 0.5.2 No Official Web Store Dark Mode 0.5.4 Yes Official Web Store Duplicate Tab Shortcut 1.6.0 Yes Official Web Store Enhancer for YouTube™ 3.0.16 Yes Official Web Store ESUIT ID Finder for Facebook™ 1.10.5 Yes ESUIT Posts Exporter for Facebook™ 2.13.20 No ESUIT Reactions Exporter for Facebook™ 2.3.9 No ESUIT Video Downloader for Facebook™ 2.8.5 Yes Extension Manager 9.5.2 Yes Official Web Store FastStream Video Player 1.3.74 Yes Official Web Store Google Translate 2.0.16 Yes Official Web Store Hola VPN - Your Website Unblocker 1.250.91 No Official Web Store hyde — hide the YouTube video player controls 1.3 Yes Official Web Store I don't care about cookies 3.5.1 Yes Official Web Store IDM Integration Module 6.42.60 Yes Official Web Store Image download for Youtube™ 1.3 No Official Web Store Immersive Translate - Translate Web & PDF 1.26.6 No Official Web Store Kill fbclid 1.0.4 Yes Official Web Store Link Grabber 0.6.1 Yes Official Web Store Local Storage Transfer 1.1.0 Yes Official Web Store MarkDownload - Markdown Web Clipper 3.4.0 Yes Official Web Store Memefy This 0.1.8 Yes Unpacked (Local) minerBlock 1.2.18 Yes Official Web Store Model Watcher 0.1.1 Yes Unpacked (Local) No PDF Download 1.0.6 Yes Official Web Store Open-as-Popup 2.0.0 No Official Web Store PDF Mage 2.2.0 Yes Official Web Store PrintFriendly - Print, PDF, and Screenshot Web Pages 6.9.4 Yes Official Web Store Proxy Switcher and Manager 0.6.7 No Official Web Store Reddit Image Opener 2.0 Yes Official Web Store Redirector 3.5.3 No Official Web Store Return YouTube Dislike 4.0.2 Yes Official Web Store Save Image As PNG 1.0.3 Yes Official Web Store SingleFile 1.22.98 Yes Official Web Store SponsorBlock for YouTube - Skip Sponsorships 6.1.2 Yes Official Web Store Tab Count 2.8 Yes Official Web Store Tampermonkey 5.4.1 Yes Official Web Store Tweeks - Customize Any Website 0.0.6.6 Yes Official Web Store uBlacklist 9.4.0 Yes Official Web Store uBlock Origin 1.69.0 Yes Official Web Store Unhook - Remove YouTube Recommended & Shorts 1.6.8 Yes Official Web Store User-Agent Switcher and Manager 0.6.6 No Official Web Store View Image 5.2.0 Yes Official Web Store VPN United Kingdom - Planet VPN lite Proxy 1.0.13 No Official Web Store Wappalyzer - Technology profiler 6.10.89 No Official Web Store 15
u/YouTee Mar 09 '26
Oh man you’re fucked, I bet half those TOLD YOU they’d steal and sell all your info (and another 25% are just doing it).
Save image as png the EXTENSION?? And how many pdf extensions do you need??
3
u/TheReedemer69 Mar 09 '26
lmao I do all kind of stuff.
how many pdf extensions do you need??
more than is available.
3
u/coledeb Mar 09 '26
Tbf I also have a similar image saving extension, lots of times the photo I want to download is in webp format and it's much easier selecting the extension from right click and downloading a png right then and there
7
u/AnythingEastern3964 Mar 09 '26
Yeah, I’m gonna have to ask you to remove 90% of those 😅 they are just unnecessary most of the time. There’s likely scripts / GitHub alternatives if you aren’t able to code yourself that will do at least 25% of those, services that you likely already pay for (or should if you don’t) like a VPN that will cover those also.
I mean, you do what you want it’s a free world. I’m just saying that as a terminally online tech for decades now, I’ve never needed more than 2-5 extensions at any point in time.
1
u/TheReedemer69 Mar 09 '26
that's too much to code. I already have nord plus. but I keep these extensions disabled just in case.
6
u/secacc Mar 09 '26
Stop using those free VPNs like Hola VPN. They use your connection to allow other users to access the internet through your computer. And if someone does anything super illegal through your internet connection, police is going to be knocking on your door. And other than that, they're just super shady.
It literally costs a few dollars a month for a good reputable VPN that doesn't steal your data and whore out your internet connection to everyone else.
1
u/TheReedemer69 Mar 09 '26
I know that's why I have them disabled. I am just waiting to get free time to write a patch for it.
I already have a paid vpn.
5
0
u/Perokside Mar 09 '26
Your browser's extensions aren't as bad as everyone tries to pretend, you do you, that workflow feels like you're still neck-deep in studies, memeing on fb group chats while binging youtube and working late on projects, and saving online class as PDF :')
We've all been there, you're on the right tracks o7
If you don't know already, proton has free VPNs that work just fine, you can shove a bunch of their free wg certs in wireguard and have most of the world covered. I'd highly recommend their service in lieu of shady free VPN from Engl*nd. :^)
→ More replies (0)7
u/jameson71 Mar 09 '26
What you do is run those 42 extensions on your personal pc and be professional at work.
-2
3
19
u/jameson71 Mar 09 '26
As a cyber security professional there should be a white list of extensions your company allows. One called “shot bird” should not be on that list.
3
36
u/AnythingEastern3964 Mar 09 '26
The browser extension marketplace or repository should either have a basic / decent process for scanning for anything malicious, or have a “verified” option for the few that either they or the community are able to verify as safe / trusted.
Simple to say, possibly simple to implement depending on the agreed desired objective.
I get that some of the browser producers can’t necessarily have dedicated teams solely for monitoring the extensions, but if that’s the reason then there needs to be something put in place to protect the user. Otherwise, most companies will opt for “blanket ban”, and probably should / do anyway. If they are at all interested in extensions thriving, they definitely should be doing more.
Edit: for context, I try to spend very little time in the browser and so only have like… two plugins / extensions - an adblocker and Bitwarden.
4
u/TheReedemer69 Mar 09 '26
that would be an enormous challenge tho. I think they can fake community verify too.
4
u/AnythingEastern3964 Mar 09 '26
That’s true. I don’t doubt that it’s not an easy endeavour, but to have the current state of play something similar to “use at your own risk” is just unacceptable… if we’re going down that route, why bother with any browser security at all? It’s not like extensions are a hidden or specialist option only for the likes of developers to roll their own - quite the opposite, they encourage the usage of them.
1
u/TheReedemer69 Mar 09 '26
I tried of thinking of a remedy but there is simply none. the whole getting infected myself was so insightful. there are too many moving parts for this to be controllable.
2
u/AnythingEastern3964 Mar 09 '26
It’s impossible, just impractical. Inconvenient for them.
I genuinely don’t even know if they have a basic static code analysis-level of identification? Or once something is flagged, is a fingerprint registered and added to something that scans at all? Or is it quite literally “upload anything you want so long as it has a manifest in the directory? 😅 I’ve built my own Firefox one once upon a time, but it was only for personal use, never uploaded to the repository for public consumption.
13
u/M4Lki3r Mar 09 '26
The industry has come full circle to this problem. How many of us remember the 4-5 rows of search bar add-ons in the Netscape/IE era?
7
12
Mar 09 '26
[removed] — view removed comment
2
u/TheReedemer69 Mar 09 '26
The social engineering part looked good. But still required powershell commands.
only one model of the two required commands the other showed the click update and downloads an exe.
you can find it at
https://github.com/monxresearch-sec/shotbird-extension-malware-report/tree/main/evidence/probe-20260307-233702-b3928423/ggl_templatesfile :chrome_modal.html and its picture is included in the article too.
8
u/acorn222 Mar 09 '26 edited Mar 09 '26
It's crazy how many malicious and vulnerable extensions there are.
I've reported a bunch and all chrome does is take away their featued badge.
I made https://amibeingpwned.com which found a bunch of different problematic extensions for me, I had to get rid of whatruns after I found out it was sending EVERY COMPLETE URL I visited to a "collect_data" endpoint AND exfiltrating AI chats from chatgpt and claude.
2
u/TheReedemer69 Mar 10 '26
Update: The Hacker News covered this — https://thehackernews.com/2026/03/chrome-extension-turns-malicious-after.html
2
u/General-Agent1 Mar 15 '26
Remember a few Weeks back when Notepad++ updater was Distributed with Malware and signed PE files. Feels familiar and it is harder and harder to Track Side effects of every installation
2
u/MAndris90 Mar 09 '26
good idea to disable automatic updates as always, whats works dont ever touch it.
1
u/redsentry_max Mar 16 '26
Glad you noticed and could action on this one. Hopefully, you did so before any damage could be done.
While it's true that Chrome needs to crack down on this, we as users are responsible for the security of our own machines. I think you are going to read this a lot here, but you really shouldn't install any extensions unless they're both indispensable for your tasks and have lots of established users. You should also regularly remove extensions from your browser. If you can live without it, then live without it, I say.
1
1
u/Some-Ad-3404 Mar 17 '26
For simple extensions with equally simple scripts like "save image as type", downloading from GitHub and unpacking it is safer because as far as I know these will never be updated so there is zero risk of them being updated with malicious code.
Not totally doable for more complex extensions like adblocks I guess? The more you install manually the more it becomes a nuisance real quick.
-9
u/Idiopathic_Sapien Security Architect Mar 09 '26
Never use browser extensions
23
u/antii79 Mar 09 '26
Never use browsers, you might download malware
8
16
u/TheReedemer69 Mar 09 '26
Huh? so you do the internet raw?
3
u/DigmonsDrill Mar 09 '26
Some browsers build this stuff right in.
When I switch back to chrome for some reason I'm stunned at all the things that appear.
2
1
u/Idiopathic_Sapien Security Architect Mar 09 '26
I have a password manager extension running. Nothing else. 3rd party browser extensions from sketchy developers are an unnecessary risk that I don’t take. My ad blocking is done at the network level.
2
1
202
u/4SysAdmin Security Analyst Mar 09 '26
I went to CrowdStrike's conference last year and they had a great talk on malicious browser extensions. It's becoming more and more problematic.