3

Google removes 32 malicious Chrome extensions with 75 million installs from the...

 1 year ago
source link: https://www.techspot.com/news/98941-google-removes-32-malicious-chrome-extensions-75-million.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Google removes 32 malicious Chrome extensions with 75 million installs from the Web Store

That number may have been inflated, though

By Rob Thubron June 5, 2023, 5:16 AM
Google removes 32 malicious Chrome extensions with 75 million installs from the Web Store
TechSpot is celebrating its 25th anniversary. TechSpot means tech analysis and advice you can trust.

In brief: It's not just the Play Store where Google has to deal with malicious software sneaking past its safeguards. The company has just removed 32 malicious extensions from the Chrome Web Store that appear to have been installed a combined 75 million times.

As is often the way in these cases, the extensions were able to hide their hidden code from users by performing their intended functions, reports BleepingComputer.

Cybersecurity researcher Wladimir Palant previously wrote that he had discovered obfuscated code in the PDF Toolbox extension for Google Chrome, which had a Chrome Web Store rating of 4.2 and more than 2 million users.

Palant wrote that the code allows the "serasearchtop[.]com" website to inject arbitrary JavaScript code into all websites that users of the extension visit. He explained the code was designed to activate 24 hours after the extension was installed, with its likely intention being the injection of ads.

2023-06-05-image.png

A couple of weeks after discovering the code in the PDF Toolbox extension, Palant wrote in a follow-up article that he had found 18 malicious browser extensions using similar code. They had a combined user count of 55 million and included Autoskip for YouTube (9 million active users), Soundboost (6.9 million), and Crystal Ad block (6.8 million).

2023-06-05-image-2.jpg

'

Avast reported the extensions to Google after it confirmed they contained malicious code. The cybersecurity giant discovered other similar extensions, taking the total to 32 and the number of installs to 75 million.

Avast did add the caveat that while that number is alarmingly high, the install counts may have been artificially inflated. It basis this theory on the suspiciously low number of reviews on the Chrome Web Store and the fact that the number of people who encountered the malicious activity didn't align with the number of installs.

Avast confirmed that the extensions' final payload appears to be adware that spams people with unwanted ads, along with a search results hijacker that displays sponsored links, paid search results, and potentially malicious links. Google said that the reported extensions have now been removed from the Chrome Store. Anyone who still has the extensions installed should deactivate or uninstall them.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK