Skip to content

ThePawn02

Gaming and Streaming Content

  • Blog
  • Editor's Picks
  • eSports
  • Guides
  • Headlines
  • News
  • Reviews
  • Uncategorized
  • Website Update
Primary Menu
  • Home
  • Watch Live
  • News
  • eSports
  • Blog
  • Reviews
  • Guides
  • Guild Login
    • Guild Mentality
    • The Zealots
    • Malign
  • Socials
    • Youtube Channel
    • Twitch Channel
    • Kick.com
    • Twitter
    • Instagram
    • Facebook
Subscribe
  • Home
  • 2025
  • April
  • Security researcher claims 35 Chrome extensions with 4,000,000+ installs ‘include some kind of spyware or infostealer’
  • News

Security researcher claims 35 Chrome extensions with 4,000,000+ installs ‘include some kind of spyware or infostealer’

Well, this can't be good.
ThePawn.com April 11, 2025 3 min read
Security researcher claims 35 Chrome extensions with 4,000,000+ installs ‘include some kind of spyware or infostealer’

Well, this can't be good.

You’d be forgiven for thinking that if you downloaded a Google Chrome extension from the official Chrome Web Store, it was likely to be above board. Not so, according to the founder of browser extension security platform Secure Annex, who claims he’s identified 35 Chrome extensions with 4 million total installs that he concludes ‘include some kind of spyware or infostealer.’

The accused extensions have several things in common. They use many of the same code patterns, connect to many of the same servers, and require the same system permissions (via Ars Technica). However, John Tuckner, founder of cybersecurity firm Secure Annex, also found they use obfuscated code that looks designed to conceal their behaviour.

“These extensions have some strong relations and most claim to actually perform some purpose like ad blocking, extension protection, better search results, or privacy protection which likely keeps them available in the web store”, says Tuckner.

“While all are different, the code for their claimed purpose is often very minimal or missing entirely.”

In the case of one particular example, Fire Shield Extension Protection, running it on a lab device resulted in a blank webpage, while clicking the options menu appeared to do nothing. Chrome developer tools revealed that the extension connected to a URL and performed a generic “browser_action_clicked” response, but nothing further.

BERLIN, GERMANY - APRIL 22: The logo of the webbrowser Google Chrome is shown on the display of a smartphone on April 22, 2020 in Berlin, Germany.

(Image credit: Getty Images. Thomas Trutschel/Photothek )

Using a unique extension ID found on GitHub, Tuckner was able to observe Fire Shield sending a variety of events to a web server, tracking what websites he was visiting, which he had visited previously, and the size of his display.

“While I could not find an instance of the [Fire Shield] extension exfiltrating credentials, this level of obfuscation alone, the ability for the extension’s configuration to be remotely controlled, and the capabilities in the browser extension’s code is enough for me to come to the same conclusion that all of these extensions include some kind of spyware or infostealer” says Tuckner.

Tuckner says that he identified 35 extensions using “eerily similar names” and with distinct similarities. 34 of them reference a mysterious “unknow.com” in their background service listings.

All but one of the identified extensions are unlisted, meaning that you’d have to click on a link directly to go to its Chrome store page. Nevertheless, 10 of the accused extensions are given the “Featured” badge by Google. As Tuckner opines:

Your next machine

Gaming PC group shot

(Image credit: Future)

Best gaming PC: The top pre-built machines.
Best gaming laptop: Great devices for mobile gaming.

“Why are some of these extensions selected to be ‘Featured’ by Google when they are not discoverable by normal users?

“This blows my mind. Any normal user might interpret that status as the extension being verified and reputable. It should absolutely not be possible to be ‘Featured’ and not discoverable at the same time.”

Indeed. You can find the full list of extensions identified by Tucker as potentially malicious at the bottom of the Ars Technica article. Many of them have names like Incognito Shield, Privacy Guard, and Total Safety, so if you’re using a Chrome extension to protect your online presence, it’s worth taking a look to see if you have some serious cleaning up to do.

About Post Author

ThePawn.com

See author's posts

Continue Reading

Previous: Ex-PlayStation exec argues ‘only the dog can hear’ differences between consoles and gaming PCs: ‘They’re all quite similar’
Next: How to get the basement key in Blue Prince

Related News

Ark: Survival Ascended celebrates 10 years of dino-dodging with a visual upgrade and letting you run around in your birthday suit
2 min read
  • News

Ark: Survival Ascended celebrates 10 years of dino-dodging with a visual upgrade and letting you run around in your birthday suit

ThePawn.com June 8, 2025
Baby Steps, Bennett Foddy’s slapstick walking simulator about a slob climbing a mountain, stumbles onto Steam in September
2 min read
  • News

Baby Steps, Bennett Foddy’s slapstick walking simulator about a slob climbing a mountain, stumbles onto Steam in September

ThePawn.com June 8, 2025
Rust’s recently added rainforest is so dense the developers changed how resources spawn because players couldn’t find them: ‘The jungle was a bit too good at being a jungle’
3 min read
  • News

Rust’s recently added rainforest is so dense the developers changed how resources spawn because players couldn’t find them: ‘The jungle was a bit too good at being a jungle’

ThePawn.com June 8, 2025

Latest YouTube Video

Check out these awesome streamers

ThePawn02 on twitch

From Gamewatcher

  • New RTS title Game of Thrones: War for Westeros coming from PlaySide in 2026
  • Jurassic World Evolution 3 revealed at Summer Game Fest, launching in October 2025 on PC, PS5, and Xbox Series X/S
  • Dune Awakening Patch Notes - 1.1.0.5 Hotfix 1
  • Cyberpunk 2077 Patch 2.3 Release Date - Latest News
  • Dune Awakening Server Status - Latest Maintenance Alerts

From IGN

  • The Biggest Reveals From IGN Live 2025 So Far
  • Sonic Racing: CrossWorlds' Takashi Iizuka on Crossover Racers Like Minecraft's Steve and How Travel Rings Change Everything - IGN Live 2025
  • MindsEye Director on the Importance of Allowing User-Generated Content in the Game | IGN Live 2025
  • Gearbox Says 'Take-Two Does Not Use Spyware in Its Games' as Borderlands Review-Bombing Continues
  • Celebrating a Decade of ARK: Survival Evolved — 10 Things Happening Now in the ARK Universe

From Kotaku

  • Splitgate 2 Dev Says He's Tired Of Playing Call Of Duty And Wants Titanfall 3 While Wearing A 'Make FPS Great Again' Hat: 'I’m Not Here To Apologize'
  • Kotaku’s Weekend Guide: 5 Great Games We’re Kicking Off The Summer With
  • Kotaku’s Biggest Gaming Culture News For The Week June 07, 2025
  • Kotaku’s Best Game Tips For The Week June 07, 2025
  • Kotaku’s Opinions For The Week June 07, 2025

.

You may have missed

Ark: Survival Ascended celebrates 10 years of dino-dodging with a visual upgrade and letting you run around in your birthday suit
2 min read
  • News

Ark: Survival Ascended celebrates 10 years of dino-dodging with a visual upgrade and letting you run around in your birthday suit

ThePawn.com June 8, 2025
How to complete all Island Stories quests in Fortnite
1 min read
  • eSports

How to complete all Island Stories quests in Fortnite

ThePawn.com June 8, 2025
Baby Steps, Bennett Foddy’s slapstick walking simulator about a slob climbing a mountain, stumbles onto Steam in September
2 min read
  • News

Baby Steps, Bennett Foddy’s slapstick walking simulator about a slob climbing a mountain, stumbles onto Steam in September

ThePawn.com June 8, 2025
Rust’s recently added rainforest is so dense the developers changed how resources spawn because players couldn’t find them: ‘The jungle was a bit too good at being a jungle’
3 min read
  • News

Rust’s recently added rainforest is so dense the developers changed how resources spawn because players couldn’t find them: ‘The jungle was a bit too good at being a jungle’

ThePawn.com June 8, 2025
Privacy Policy
  • Home
  • Watch Live
  • News
  • eSports
  • Blog
  • Reviews
  • Guides
  • Guild Login
  • Socials
  • Twitch
  • YouTube
  • Instagram
  • Twitter
  • Facebook
  • Kick.com
Copyright © All rights reserved. | MoreNews by AF themes.