Skip to main content
  1. Home
  2. Computing
  3. News

Chrome extensions with 1.4M users may have stolen your data

Add as a preferred source on Google

McAfee researchers have discovered various Google Chrome extensions that steal browsing activity, with the add-ons racking up more than a million downloads.

As reported by Bleeping Computer, threat analysts at the digital security company have come across a total of five such malicious extensions.

Google Chrome icon in mac dock.
PixieMe / Shutterstock

With more than 1.4 million downloads, the extensions have tricked an unprecedented number of individuals into adding them to their browsers. The extensions in question that have been tracked down thus far are:

  • Netflix Party (mmnbenehknklpbendgmgngeaignppnbe) — 800,000 downloads
  • Netflix Party 2 (flijfnhifgdcbhglkneplegafminjnhn) — 300,000 downloads
  • Full Page Screenshot Capture — Screenshotting (pojgkmkfincpdkdgjepkmdekcahmckjp) — 200,000 downloads
  • FlipShope — Price Tracker Extension (adikhbfjdbjkhelbdnffogkobkekkkej) — 80,000 downloads
  • AutoBuy Flash Sales (gbnahglfafmhaehbdmjedfhdmimjcbed) — 20,000 downloads
Recommended Videos

Once one of the extensions listed above has been installed onto Chrome, it can subsequently detect and observe when the user opens an e-commerce website on their browser. The cookie that is generated by the visitor is altered in order to make it seem they arrived at the site via a referrer link. Ultimately, whoever is behind the extensions can then receive an affiliate fee should the target buy anything from these sites.

All the extensions actually deliver on whatever functionality is listed on their Chrome web store pages. Coupled with the fact that they showcase a user base in the tens or hundreds of thousands, it may convince many that they’re safe to download if they’re being utilized by so many individuals.

While the Netflix Party extensions have been taken down, the screenshot and price tracker ones are still live on the Chrome web store.

As for how the extensions work, McAfee detailed how the web app manifest — an element controlling how the add-ons run on the browser — executes a multifunctional script, allowing browsing data to be sent directly to the attackers through a certain domain that they’ve registered.

Once a user visits a new URL, their browsing data is sent with the use of POST requests. Such information includes the website address itself (in base64 form), the user ID, device location (country, city, and zip code), and a referral URL that’s encoded.

To avoid being detected, some of the extensions won’t activate their malicious tracking activity until 15 days after it’s been installed by the target. Similarly, we’ve recently seen how threat actors delay their malware being loaded onto a system for up to a month.

Hackers have increasingly relied on hiding malicious codes and malware in free Windows software and downloads. Most recently, they’ve been targeting users with space images, as well as trying to breach systems via Windows Calculator.

Zak Islam
Former Contributor
Zak covers the latest news in the technology world, particularly the computing field. A fan of anything pertaining to tech…
Adobe’s new AI assistant could save you hours in Photoshop and Premiere
Premiere Pro users may never have to rename 500 video clips again
Adobe

Adobe is making one of its biggest bets yet on AI-powered creativity. The company has announced a major expansion of its creative agent across Firefly and Creative Cloud, introducing AI assistants capable of handling complex, multi-step workflows across applications, including Photoshop, Premiere Pro, Illustrator, InDesign, and Frame.io.

The move positions Adobe's AI agent as a central layer connecting every stage of the creative process, from brainstorming and content generation to editing and final production. Rather than simply generating images or text, Adobe's vision is to create an assistant that can understand a creator's goal and execute a series of actions across multiple tools.

Read more
Trump says Intel will make chips for Apple in a major win for U.S. manufacturing
Intel Foundry may have landed its most important customer yet
Logo

Intel’s efforts to rebuild its chipmaking business may have landed its biggest customer yet. U.S. President Donald Trump announced on Thursday that Apple has agreed to work with Intel to design and manufacture chips in the United States, a deal that could significantly strengthen Intel’s foundry ambitions.

The announcement does not come out of the blue. Earlier reports indicated that Apple and Intel had been discussing a manufacturing partnership for more than a year and had already begun working together on select chip production projects.

Read more
A harmless-looking ChatGPT prompt opened the door to gruesome AI images
The findings show how image safety systems can fail without explicit graphic instructions.
ChatGPT

A harmless-looking ChatGPT prompt pushed the latest public version of ChatGPT into generating sexualized and violent images, AI security researchers told the BBC. The finding puts new pressure on OpenAI’s image safety systems, since the request wasn’t described as plainly graphic.

Mindgard, a British AI security startup, said it reached the results by altering a widely shared instruction that had been used for comedy. OpenAI added safeguards after the BBC contacted it, but the researchers said small wording changes still produced concerning images.

Read more