Chrome and Firefox extensions stealing customer data

chrome firefox extensions
(Image credit: Shutterstock.com) (Image credit: Shutterstock)

Users of Chrome and Firefox have been warned to check their browser extensions after a number of popular tools were found to be collecting and selling user data without permission.

Six extensions have been found to be hoovering up user information, an investigation by the Washington Post found, with data sent to a centralised platform.

Among the most popular tools were Hover Zoom, SpeakIt!, SuperZoom, SaveFrom.net Helper, FairShare Unlock and PanelMeasurement - all of which were avilable on Chrome, with two on offer to Firefox users. Overall, the extensions had been installed over four million times worldwide.

Data gathering

Dubbed DataSpii by security researcher Sam Jadali, the platform collated data collected by the apps and extensions over aperiod of time. Some extensions began gathering data immediately, but some waited several weeks to begin, with the average being 24 days.

This delay often meant users were not initially able to spot that anything was amiss, with Google and Mozilla researchers also apparently unaware anything was wrong. After this time, the extensions would download a JavaScript payload from Internet servers that included the data collecting code, but used clever methods to disguise what they were doing.

Jadali noted that these servers were linked back to analytics firm Nacho Analytics, which also had information on internal link data of major corporations such as Apple and Tesla.

All the extensions have now been remvoed from the Chrome and Firefox web stores, but users should still check to ensure their browsers are not at risk.

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off