Browser Extension Malware Hits 2.3 Million Chrome Users
Google removed 41 Chrome extensions on September 14 after researchers found they were harvesting login cookies from roughly 2.3 million installs.
By Mara Voss, Technology
· 2 min read · Updated
Key Takeaways
- •Google removed 41 Chrome extensions on September 14 that had collectively been installed 2.3 million times.
- •The extensions stole session cookies, which can let an attacker access accounts without a password.
- •Security firm Halberd Security first reported the extensions to Google on August 22; removal took 23 days.
- •Users should review permissions on any browser extension installed in the past year and remove unused ones.
Google removed 41 Chrome extensions from its Web Store on September 14 after a security research firm found they were quietly copying users' login session cookies and sending them to a remote server. Combined, the extensions had been installed roughly 2.3 million times.
The extensions, mostly disguised as PDF converters, ad blockers, and color-picker tools, had been available in the Web Store for an average of 14 months before being flagged, according to the researchers who found them.
How the malware worked
The Short Answer
The malicious extensions requested broad browser permissions, then used those permissions to copy session cookies for sites like Gmail and major banks, sending the data to a remote server every six hours. Google has removed all 41 extensions and revoked the developer accounts behind them.
Session cookies are what keep you logged into a website without re-entering your password every time. If someone steals that cookie, they can often access your account directly, bypassing your password and even two-factor authentication in some cases.
2.3 million
combined installs across the 41 removed extensions
The five most-installed extensions accounted for 1.1 million of the total, roughly half.
The research firm, Halberd Security, said it first flagged the pattern to Google on August 22, and Google took 23 days to remove all 41 extensions after verifying the report.
“These extensions asked for permissions no PDF converter needs. That mismatch between what an app does and what it asks for is the single easiest scam to catch, and also one of the easiest ones to keep missing.”
What this means for you
If you installed a PDF, screenshot, or ad-blocking extension in the last 14 months, check Chrome's extension list at chrome://extensions and remove anything you do not actively use. Google has published the list of the 41 removed extensions by name.
Beyond this specific incident, the fix is a habit: check an extension's requested permissions before installing, and be suspicious of any simple tool, a PDF converter, a color picker, that asks for permission to read and change all your data on all websites. That phrase is the browser's own warning label.
- cybersecurity
- Google Chrome
- browser extensions
- data privacy
Sources
- 01Chrome Web Store Enforcement Update, Googleblog.google
- 02Cookie Theft Campaign Report, Halberd Securityexample.com
Corrections
No corrections have been made to this article.
About the reporter
Technology Reporter, Trestlewire
I spent seven years as a product manager at a mid-size SaaS company before switching sides to cover the industry that used to sign my paychecks. That means I have sat in the roadmap meetings, and I know the difference between a feature that ships and a slide that gets a demo clap.
Read full bio and all stories →