of blocking a series of malicious browser extensions for Chrome that affected several million users. Initially, independent researcher Jamila Kaya () and Duo Security identified 71 malicious extensions in the Chrome Web Store. In total, these extensions had more than 1.7 million installations. After informing Google about the issue, over 430 similar extensions were discovered in the catalog, the number of installations for which has not been disclosed.
Notably, despite the impressive number of installations, none of the problematic extensions have user reviews, raising questions about how these extensions were installed and how the malicious activity went unnoticed. Currently, all problematic extensions have been removed from the Chrome Web Store.
According to researchers, the malicious activity linked to the blocked extensions has been ongoing since January 2019, but certain domains used for malicious actions were registered back in 2017.
The majority of malicious extensions were presented as tools for product promotion and participation in advertising services (users view ads and receive payments). The extensions employed a technique of redirecting to advertised websites when opening pages that were shown in sequence before displaying the requested site.
All extensions used a similar technique to conceal malicious activity and bypass verification mechanisms in the Chrome Web Store. The code of all extensions was almost identical at the source code level, except for the function names, which were unique in each extension. The transmission of malicious logic was carried out from centralized control servers. Initially, the extension connected to a domain that had the same name as the extension (for example, Mapstrek.com), after which it redirected to one of the control servers that delivered the script for further actions.
Among the actions performed through the extensions, there are mentions of uploading confidential user data to external servers, redirecting to malicious websites, and facilitating the installation of malware (for example, a message appears about a computer infection, and malicious software is offered under the guise of antivirus or browser updates). The domains to which redirection occurred include various phishing domains and sites exploiting outdated browsers with unpatched vulnerabilities (for instance, after exploitation, attempts were made to install malware that intercepts access keys and analyzes the transmission of confidential data via the clipboard).
Source: opennet.ru
