Your browser extensions may be secretly hiding a botnet

Privacy
(Image credit: Shutterstock / Valery Brozhinsky)

One of the world's leading cybersecurity experts has revealed how a company that was paying to include its code in browser extensions was actually doing so in order to mask the real IP address of its own customers, who might be using the service for nefarious purposes.

Brian Krebs, together with developer of the ModHeader browser extension, Hao Nguyen, has shared details about Infatica’s program, which is just one of several that pay developers to include their code within the browser extensions

“For its part, Infatica seeks out authors with extensions that have at least 50,000 users. An extension maker who agrees to incorporate Infatica’s computer code can earn anywhere from $15 to $45 each month for every 1,000 active users,” shares Krebs.

Too good to refuse

Infatica is a proxy service provider that retails rotating backconnect residential proxies. It was one of the several companies that approached Nguyen to include its code in his extension.

After failing to monetize his extension for several years, Nguyen finally relented as the Infatica offer would have made him at least $1500 a month. Plus, Infatica’s code was fairly straightforward and limited itself to just routing web requests through the browsers of Nguyen’s users.

“The end result is when Infatica customers browse to a web site, that site thinks the traffic is coming from the Internet address tied to the extension user, not the customer’s,” explains Krebs.

While Nguyen was quick to sign out of the program, after his users complained, Krebs research revealed that at least three dozen extensions are using Infatica’s code. Many of these have over 100,000 users, reveals Krebs, including Video Downloader Plus, which is one of the most popular Chrome extensions for downloading media from several websites.

Krebs’ research once again highlights the unscrupulous use of extensions by shady services that prey on the economic vulnerabilities of extension developers. He echoes our suggestion to users to only use the bare essential third-party extensions, and be vary of any that suddenly ask for more permissions than previous versions.

Via: KrebsOnSecurity

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
chrome firefox extensions
Google Chrome extensions hit in major attack - dozens of developers affected, so be on your guard
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
Google Chrome browser app on iPhone
Best Chrome VPN extension of 2025
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Chrome icon on Android
Google Chrome extensions hack may have started much earlier than expected
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Nikon Z5
The Nikon Z5 II could land soon – here's what to expect from Nikon's rumored entry-level full-frame camera
Google Pixel Watch 3
Google Pixel Watches hit with delayed notifications, crashing, and performance issues following Wear OS 5.1 update
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now