Google removes malicious Chrome extensions with half a million downloads

Google Chrome on a laptop

Google has removed four malicious browser extensions with a combined total of 500,000 downloads from the Chrome Web Store. 

Security firm ICEBRG discovered the malicious extensions after it picked up an unusual spike in outgoing network traffic. The first extension identified was called HTTP Request Header. After further investigation, it discovered three more: Nyoogle, Stickies and Lite Bookmarks.

In a blog post, ICEBRG said that although the extensions were probably used to commit click fraud (imitating the process of a user clicking an ad in their browser) or manipulate search engine results, they could be used to create a botnet with the potential to access business networks and user information. 

“Removal of the malicious extension from the Chrome Web Store may not remove it from impacted hosts,” ICEBRG added. “Additionally, the use of third-party Chrome extension repositories may still allow the installation of the extensions.”

It’s possible that the number of downloads could have been inflated through use of bots to make the extensions seem legitimate and trick more people into installing the malware.

Verifying browser extensions

Each browser developer takes a different approach to verifying the quality and safety of add-ons in their stores.

Before publication on the Google Chrome Web Store, extensions are subjected to a process called Enhanced Item Evaluation – a series of automated checks that examine its code and behavior once installed to identify malware. Once the validation is complete, the app is published – usually within an hour.

The process normally works well, but sometimes extensions slip through the net. For example, in October last year, 37,000 people downloaded a fake version of Adblock Plus that was almost impossible to differentiate from the real thing.

Microsoft launched an extension store for Edge in 2016, and tests each submission individually before it's published – a process than can take 72 hours. 

Mozilla takes a more liberal approach. All Firefox add-ons must comply with a set of policies and practices that varies depending on circumstances. Extensions listed on addons.mozilla.org may be subject to automatic and manual review and testing, during which they won’t appear in search results, but will still be accessible if you have a link to their listing pages.

Unlisted add-ons aren’t subjected to quite such strict standards. They must still be uploaded to addons.mozilla.org, but have to be distributed elsewhere.

Via: Ars Technica

TOPICS
Cat Ellis
Homes Editor

Cat is TechRadar's Homes Editor specializing in kitchen appliances and smart home technology. She's been a tech journalist for 15 years and is an SCA-certified barista, so whether you want to invest in some smart lights or pick up a new espresso machine, she's the right person to help.

Latest in Chrome
Google Chrome browser icon
A new split-screen feature is coming to Google Chrome, and it's surprisingly powerful
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
Close-up of Asus Chromebook CM14 ports on left side
Are you an educator or student? Google's new features for Chromebooks and more will make your life way easier
Chrome icon on Android
Google plans on a handy fix for all those duplicate Chrome tabs, but it's only for Android
A trophy with the Chrome logo on it and a star with "2024" written in it
These are the best Chrome Extensions of 2024 – according to Google
Close up of Chromebook
Chrome slowing down your laptop? Google’s new performance controls could help the browser run faster
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras