Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security issue: Can't detect malware extension #44

Open
jinxx0 opened this issue Oct 20, 2020 · 2 comments
Open

Security issue: Can't detect malware extension #44

jinxx0 opened this issue Oct 20, 2020 · 2 comments

Comments

@jinxx0
Copy link

jinxx0 commented Oct 20, 2020

If the malware extension is removed in Chrome, opera cannot detect it. On October 18, the extension "Nano Adblock & Nano Defender" collected all cookies from Instagram and hacked 100K accounts

@alexweissman
Copy link

This happened to me with "User Agent Switcher". I'm not exactly sure how this extension works, but it looks like it may have installed one of the new, infected versions of the extension without informing me or updating the version string:

Screen Shot 2021-03-23 at 2 52 15 PM

Supposedly version 1.8.6.3 is not an infected version, but then when I look at the actual source code I can see that it opens up a socket to useragentswitch.com. This gives an attacker a full C&C access to my browser as described here: https://github.com/partridge-tech/chris-blog/blob/main/_content/2020/extensions-the-next-generation-of-malware/user-agent-switcher.md

@krystian3w
Copy link

Yes, ICE was updating extensions in the background so that users would not stay on the old version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants
@alexweissman @krystian3w @jinxx0 and others