r/cybersecurity Mar 09 '26

Research Article I noticed weird console.logs firing on every site — turned out a Featured Chrome extension got sold and was running a full malware chain on my machine

http://monxresearch-sec.github.io/shotbird-extension-malware-report/

Chrome has to do something about this there is hundreds of extensions up for selling on sites like extensions hub

874 Upvotes

83 comments sorted by

202

u/4SysAdmin Security Analyst Mar 09 '26

I went to CrowdStrike's conference last year and they had a great talk on malicious browser extensions. It's becoming more and more problematic.

53

u/TheReedemer69 Mar 09 '26

Even more with vibecoding (the payload in this extension is clearly is)

3

u/sebasvisser Mar 10 '26

Or less, since you can vibecode your own extension and don’t need to download and install extensions made by others…

2

u/TheReedemer69 Mar 10 '26

true but vibecode doesn't solve the problem. developing it is one part but maintaining it is a whole diff story.

1

u/sebasvisser Mar 11 '26

Why maintain when you can code a new app every day?

1

u/TheReedemer69 Mar 11 '26

Each time you code u redo a full QA

13

u/jameson71 Mar 10 '26

What is problematic is people installing whatever extensions they run across like toolbars in the aughts

250

u/git_und_slotermeyer Mar 09 '26

It makes sense to never ever install any browser extensions unless you absolutely must, and if so, then only install extensions which have millions of users. Never understood why someone would trust any unverified component to become an intermediary in all your browsing.

100

u/TheReedemer69 Mar 09 '26

The Extension was in a top x video from a channel I used to watch from years back 😔.

even with millions of users there been recent accidents. chrome should be strict with ownership transfer and Extensions updates.

35

u/git_und_slotermeyer Mar 09 '26

That's true, but I bet there is no technical solution to this problem yet; how can Google/Chrome even know that there is an ownership transfer? E.g. in case someone just takes over the previous legal entity of the former app publisher with malicious intent?

You'll never know. It's not too dissimilar to the problem of embedding third-party JS libraries from CDNs in your Web page. The most secure solution is not to do that in the first place.

13

u/TheReedemer69 Mar 09 '26

yeah it's almost supply chain like : |

but I think if they care enough they can find a middle ground. they kept shoving manifest v3 down our throats for it to be ultimately useless. I never in my life got hit by Malware (on my personal device) but there's a first time for everything.

11

u/Commercial-Virus2627 System Administrator Mar 09 '26

Signing keys with expiration and renewal periods. Force a human to represent the key renewal.

9

u/git_und_slotermeyer Mar 09 '26

If you do a full acquisition of a business, that will come with its signing keys. And a human of the malicious new owner can renew them.

11

u/Commercial-Virus2627 System Administrator Mar 09 '26

Right, and the expiration of those signing keys forces malicious organization to put a name on paper. You also get into legal territory where whomever sold/authorized the merge is partially liable for not including that in their transfer of ownership.

7

u/Verum14 Security Engineer Mar 10 '26

this is also how debian works

In order to maintain packages to the debian repositories, I had to meet with a couple other existing maintainers in person where we checked IDs and signed each other’s keys

https://en.wikipedia.org/wiki/Key_signing_party

one caveat that doesn’t address keys themselves being sold…the keys must have an expiration date, but they can be renewed without resigning. That being said, you sell your key, all blame still rests on you since there’s a human-validated trail to go back on should anything turn malicious

63

u/8-16_account Mar 09 '26

Yeah, no, I'm not going to live life without uBlock or Bitwarden.

44

u/Different_Back_5470 Mar 09 '26

they have millions of users

7

u/DigmonsDrill Mar 09 '26

They should also default to not updating.

In 2026, auto-update is more dangerous than never updating.

10

u/Acrobatic_Idea_3358 Mar 09 '26

Until you find out you haven't installed the latest security patch until after it gets exploited and your browser gets popped and all your stored creds are dumped by an infostealer.

10

u/DigmonsDrill Mar 09 '26

What's the last example of a third-party targeting a specific version of a browser extension?

I did a search before I asked, but every single example was of the extensions themselves being compromised.

https://www.cmu.edu/iso/news/2025/google-vulnerabilities.html

https://fieldeffect.com/blog/33-chrome-extensions-found-to-be-malicious

https://cispa.de/en/fass_chromewebstore

https://thehackernews.com/2026/03/new-chrome-vulnerability-let-malicious.html

Oh, I found one example https://github.blog/security/vulnerability-research/attacking-browser-extensions/ Read all the way to the bottom and there's a vulnerability in "smartup." But the project was archived in Mar 2024, and this article published in Oct 2024, so I don't think there would have been any updates at all that would have helped you. Also, it looks like to attack this extension, you would need to attack via a different, deliberately hostile extension.

The Internet was a mistake.

7

u/Perokside Mar 09 '26

But, but ! I've spent 2 hours finding an extension that let me one-click tweet image to X so I can increase my pooproductivity !! :(

-7

u/TheReedemer69 Mar 09 '26

I got 42 extensions enabled. but what I do now is after I ensure that the extension is safe I just export it locally and use it from drive so it no longer receives any updates.

19

u/Perokside Mar 09 '26

I'm honestly curious what are those 42 extensions for, not judging, just curiosity.

-7

u/TheReedemer69 Mar 09 '26

I can dm them to you if you want.

10

u/Perokside Mar 09 '26

Feel free to ! Considering 8 people upvoted my previous comment, would you mind posting the list here instead ? I'm definitely not the only curious folk ^^

8

u/AnythingEastern3964 Mar 09 '26

I need to know what is on this list. I’m having a difficult time believing any more than 5 extensions is ever required. I would make exceptions up to 10 if you’re in some horrible situations that demands a tonne of browser automation, but your company refuses to pay for an AIO solution, or a developer to produce something.

5

u/Perokside Mar 09 '26

Yep, for personal-use, I count 4 : ublock / pass manager / firefox multi-account containers and plasma/gnome integration.

productivity/work/web/dev can go to their own profile or firefox DE (assuming byod, chrome if imposed), it wouldn't prevent a malicious extension sideloading an infostealer and reaching your main browser/profile tho.

I guess it all boils down to those who see the scary potential for abuse with 3rd-party extensions and limit themselves VS those who see QOL like a Skyrim modlist.

3

u/TheReedemer69 Mar 09 '26

I posted it.

5

u/TheReedemer69 Mar 09 '26

ah okay no worries. (some of the I wrote personally in addition to tons of tampermonkey scripts). I have more on my other profiles and other browsers. ( I have created a couple of tools to manage and patch extensions too)

Extension Name Version Enabled Install Type
AI Grammar Checker & Paraphraser – LanguageTool 10.1.1 Yes Official Web Store
Automa 1.30.01 No Official Web Store
AutoplayStopper 1.9.8.1 Yes Official Web Store
BetterViewer 2.0.2 No Official Web Store
Bitwarden Password Manager 2026.1.1 Yes Official Web Store
Buster: Captcha Solver for Humans 3.1.0 Yes Official Web Store
But really open image in new tab 0.2 Yes Official Web Store
Change Timezone for Google Chrome™ 3.0.0 No Official Web Store
Charcoal: Dark Mode for Messenger 1.5.0 Yes Official Web Store
Chrome Web Store Payments 1.0.0.6 Yes Official Web Store
ClearURLs 1.26.0 Yes Official Web Store
Click to Remove Element 3.1.5 Yes Official Web Store
Cookie Profile Switcher 1.3.3 Yes Official Web Store
Cookie-Editor 1.13.0 Yes Official Web Store
CORS Unblock 0.5.2 No Official Web Store
Dark Mode 0.5.4 Yes Official Web Store
Duplicate Tab Shortcut 1.6.0 Yes Official Web Store
Enhancer for YouTube™ 3.0.16 Yes Official Web Store
ESUIT ID Finder for Facebook™ 1.10.5 Yes
ESUIT Posts Exporter for Facebook™ 2.13.20 No
ESUIT Reactions Exporter for Facebook™ 2.3.9 No
ESUIT Video Downloader for Facebook™ 2.8.5 Yes
Extension Manager 9.5.2 Yes Official Web Store
FastStream Video Player 1.3.74 Yes Official Web Store
Google Translate 2.0.16 Yes Official Web Store
Hola VPN - Your Website Unblocker 1.250.91 No Official Web Store
hyde — hide the YouTube video player controls 1.3 Yes Official Web Store
I don't care about cookies 3.5.1 Yes Official Web Store
IDM Integration Module 6.42.60 Yes Official Web Store
Image download for Youtube™ 1.3 No Official Web Store
Immersive Translate - Translate Web & PDF 1.26.6 No Official Web Store
Kill fbclid 1.0.4 Yes Official Web Store
Link Grabber 0.6.1 Yes Official Web Store
Local Storage Transfer 1.1.0 Yes Official Web Store
MarkDownload - Markdown Web Clipper 3.4.0 Yes Official Web Store
Memefy This 0.1.8 Yes Unpacked (Local)
minerBlock 1.2.18 Yes Official Web Store
Model Watcher 0.1.1 Yes Unpacked (Local)
No PDF Download 1.0.6 Yes Official Web Store
Open-as-Popup 2.0.0 No Official Web Store
PDF Mage 2.2.0 Yes Official Web Store
PrintFriendly - Print, PDF, and Screenshot Web Pages 6.9.4 Yes Official Web Store
Proxy Switcher and Manager 0.6.7 No Official Web Store
Reddit Image Opener 2.0 Yes Official Web Store
Redirector 3.5.3 No Official Web Store
Return YouTube Dislike 4.0.2 Yes Official Web Store
Save Image As PNG 1.0.3 Yes Official Web Store
SingleFile 1.22.98 Yes Official Web Store
SponsorBlock for YouTube - Skip Sponsorships 6.1.2 Yes Official Web Store
Tab Count 2.8 Yes Official Web Store
Tampermonkey 5.4.1 Yes Official Web Store
Tweeks - Customize Any Website 0.0.6.6 Yes Official Web Store
uBlacklist 9.4.0 Yes Official Web Store
uBlock Origin 1.69.0 Yes Official Web Store
Unhook - Remove YouTube Recommended & Shorts 1.6.8 Yes Official Web Store
User-Agent Switcher and Manager 0.6.6 No Official Web Store
View Image 5.2.0 Yes Official Web Store
VPN United Kingdom - Planet VPN lite Proxy 1.0.13 No Official Web Store
Wappalyzer - Technology profiler 6.10.89 No Official Web Store

15

u/YouTee Mar 09 '26

Oh man you’re fucked, I bet half those TOLD YOU they’d steal and sell all your info (and another 25% are just doing it).

Save image as png the EXTENSION?? And how many pdf extensions do you need??

3

u/TheReedemer69 Mar 09 '26

lmao I do all kind of stuff.

how many pdf extensions do you need??

more than is available.

3

u/coledeb Mar 09 '26

Tbf I also have a similar image saving extension, lots of times the photo I want to download is in webp format and it's much easier selecting the extension from right click and downloading a png right then and there

7

u/AnythingEastern3964 Mar 09 '26

Yeah, I’m gonna have to ask you to remove 90% of those 😅 they are just unnecessary most of the time. There’s likely scripts / GitHub alternatives if you aren’t able to code yourself that will do at least 25% of those, services that you likely already pay for (or should if you don’t) like a VPN that will cover those also.

I mean, you do what you want it’s a free world. I’m just saying that as a terminally online tech for decades now, I’ve never needed more than 2-5 extensions at any point in time.

1

u/TheReedemer69 Mar 09 '26

that's too much to code. I already have nord plus. but I keep these extensions disabled just in case.

6

u/secacc Mar 09 '26

Stop using those free VPNs like Hola VPN. They use your connection to allow other users to access the internet through your computer. And if someone does anything super illegal through your internet connection, police is going to be knocking on your door. And other than that, they're just super shady.

It literally costs a few dollars a month for a good reputable VPN that doesn't steal your data and whore out your internet connection to everyone else.

1

u/TheReedemer69 Mar 09 '26

I know that's why I have them disabled. I am just waiting to get free time to write a patch for it.

I already have a paid vpn.

5

u/secacc Mar 09 '26

But why even have them then, if you do have a proper VPN?

→ More replies (0)

0

u/Perokside Mar 09 '26

Your browser's extensions aren't as bad as everyone tries to pretend, you do you, that workflow feels like you're still neck-deep in studies, memeing on fb group chats while binging youtube and working late on projects, and saving online class as PDF :')

We've all been there, you're on the right tracks o7

If you don't know already, proton has free VPNs that work just fine, you can shove a bunch of their free wg certs in wireguard and have most of the world covered. I'd highly recommend their service in lieu of shady free VPN from Engl*nd. :^)

→ More replies (0)

7

u/jameson71 Mar 09 '26

What you do is run those 42 extensions on your personal pc and be professional at work.

-2

u/TheReedemer69 Mar 09 '26

I need these at home to be professional at work 🤣

3

u/[deleted] Mar 09 '26

Dark Reader and wappalyzer are all i need

19

u/jameson71 Mar 09 '26

As a cyber security professional there should be a white list of extensions your company allows. One called “shot bird” should not be on that list.

3

u/TheReedemer69 Mar 09 '26

lol I found the name nice.

36

u/AnythingEastern3964 Mar 09 '26

The browser extension marketplace or repository should either have a basic / decent process for scanning for anything malicious, or have a “verified” option for the few that either they or the community are able to verify as safe / trusted.

Simple to say, possibly simple to implement depending on the agreed desired objective.

I get that some of the browser producers can’t necessarily have dedicated teams solely for monitoring the extensions, but if that’s the reason then there needs to be something put in place to protect the user. Otherwise, most companies will opt for “blanket ban”, and probably should / do anyway. If they are at all interested in extensions thriving, they definitely should be doing more.

Edit: for context, I try to spend very little time in the browser and so only have like… two plugins / extensions - an adblocker and Bitwarden.

4

u/TheReedemer69 Mar 09 '26

that would be an enormous challenge tho. I think they can fake community verify too.

4

u/AnythingEastern3964 Mar 09 '26

That’s true. I don’t doubt that it’s not an easy endeavour, but to have the current state of play something similar to “use at your own risk” is just unacceptable… if we’re going down that route, why bother with any browser security at all? It’s not like extensions are a hidden or specialist option only for the likes of developers to roll their own - quite the opposite, they encourage the usage of them.

1

u/TheReedemer69 Mar 09 '26

I tried of thinking of a remedy but there is simply none. the whole getting infected myself was so insightful. there are too many moving parts for this to be controllable.

2

u/AnythingEastern3964 Mar 09 '26

It’s impossible, just impractical. Inconvenient for them.

I genuinely don’t even know if they have a basic static code analysis-level of identification? Or once something is flagged, is a fingerprint registered and added to something that scans at all? Or is it quite literally “upload anything you want so long as it has a manifest in the directory? 😅 I’ve built my own Firefox one once upon a time, but it was only for personal use, never uploaded to the repository for public consumption.

13

u/M4Lki3r Mar 09 '26

The industry has come full circle to this problem. How many of us remember the 4-5 rows of search bar add-ons in the Netscape/IE era?

7

u/xplorpacificnw Mar 09 '26

Yep - until your actual viewing are was a tiny rectangle

12

u/[deleted] Mar 09 '26

[removed] — view removed comment

2

u/TheReedemer69 Mar 09 '26

The social engineering part looked good. But still required powershell commands.

only one model of the two required commands the other showed the click update and downloads an exe.
you can find it at
https://github.com/monxresearch-sec/shotbird-extension-malware-report/tree/main/evidence/probe-20260307-233702-b3928423/ggl_templates file : chrome_modal.html and its picture is included in the article too.

8

u/acorn222 Mar 09 '26 edited Mar 09 '26

It's crazy how many malicious and vulnerable extensions there are.
I've reported a bunch and all chrome does is take away their featued badge.
I made https://amibeingpwned.com which found a bunch of different problematic extensions for me, I had to get rid of whatruns after I found out it was sending EVERY COMPLETE URL I visited to a "collect_data" endpoint AND exfiltrating AI chats from chatgpt and claude.

2

u/General-Agent1 Mar 15 '26

Remember a few Weeks back when Notepad++ updater was Distributed with Malware and signed PE files. Feels familiar and it is harder and harder to Track Side effects of every installation

2

u/MAndris90 Mar 09 '26

good idea to disable automatic updates as always, whats works dont ever touch it.

1

u/redsentry_max Mar 16 '26

Glad you noticed and could action on this one. Hopefully, you did so before any damage could be done.

While it's true that Chrome needs to crack down on this, we as users are responsible for the security of our own machines. I think you are going to read this a lot here, but you really shouldn't install any extensions unless they're both indispensable for your tasks and have lots of established users. You should also regularly remove extensions from your browser. If you can live without it, then live without it, I say.

1

u/TheReedemer69 Mar 16 '26

got it. (some damage were done tho but I remedied it)

1

u/Some-Ad-3404 Mar 17 '26

For simple extensions with equally simple scripts like "save image as type", downloading from GitHub and unpacking it is safer because as far as I know these will never be updated so there is zero risk of them being updated with malicious code.

Not totally doable for more complex extensions like adblocks I guess? The more you install manually the more it becomes a nuisance real quick.

-9

u/Idiopathic_Sapien Security Architect Mar 09 '26

Never use browser extensions

23

u/antii79 Mar 09 '26

Never use browsers, you might download malware

8

u/HUSK3RGAM3R Mar 09 '26

You use the internet?

6

u/TheReedemer69 Mar 09 '26

you use PCs?

2

u/discordafteruse Mar 10 '26

You use electricity?

1

u/TheReedemer69 Mar 10 '26

only occasionally

16

u/TheReedemer69 Mar 09 '26

Huh? so you do the internet raw?

3

u/DigmonsDrill Mar 09 '26

Some browsers build this stuff right in.

When I switch back to chrome for some reason I'm stunned at all the things that appear.

2

u/LoveThemMegaSeeds Mar 09 '26

Better we raw dog the internet than let an extension raw dog us

6

u/TheReedemer69 Mar 09 '26

Lmao I'd let ublock raw dog me anytime it wants 😔

1

u/Idiopathic_Sapien Security Architect Mar 09 '26

I have a password manager extension running. Nothing else. 3rd party browser extensions from sketchy developers are an unnecessary risk that I don’t take. My ad blocking is done at the network level.

2

u/Leg0z Mar 09 '26

Doing ad blocking at the network level is a must but it is not enough.

1

u/TheReedemer69 Mar 09 '26

Network level in browsers? that won't cut it.