Google Chrome: legit EditThisCookie extension removed instead of malicious copycat
#1
Exclamation 
Quote:EditThisCookie is a specialized extension for Google Chrome that you may use to edit cookie data stored by the browser. I mentioned it back in 2015 here on Ghacks.

The extension, with over 3 million users and 11,000 ratings, has been removed from the Chrome Web Store. What Google has not removed is a copycat extension, first called EditThisCookies and now EditThisCookie®, which is malicious.

When you try to launch the Chrome Web Store address of the legitimate extension, you get the "This item is not available" error message. The page of the fake extension is still up (not linked, because it is malicious).

Eric Parker, known for his malware investigations, analyzed the malicious extension in a YouTube video.

The extension had 30,000 users at the time the video was published on YouTube. Today, it sits at more than 50,000 users.

Parker installed the extension on a test system and discovered several anomalies. These include:
  • A fake website for the fake extension.
  • Obfuscated code.
  • Information stealing code, especially when on Facebook.
  • Phishing.
  • Advertising code.
The researcher did not find code to exfiltrate cookie data, which means that session cookies are not touched by the analyzed version of the extension.

With automatic extension updates enabled by default in Chrome, there is a chance that additional spyware or malware capabilities are added via updates.

Contnue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Intel Graphics Driver 32.0.101.7088 / 10...
Homepage Download...harlan4096 — 10:05
Privazer 4.0.124.2
v4.0.124.2 (01 Jul...harlan4096 — 09:58
Google Chrome 150.0.7871.46/.47
Google Chrome 150....harlan4096 — 09:55
Kali Linux 2026.2 Released With 9 New To...
Offensive Security...harlan4096 — 08:28
INTEL Arc Graphics 32.0.101.8860 driver
INTEL Arc Graphics...harlan4096 — 08:19

[-]
Birthdays
Today's Birthdays
avatar (41)optsaZes
avatar (40)RaymondViata
Upcoming Birthdays
avatar (47)dapedDow
avatar (49)TromPerl
avatar (46)RidgeDimb
avatar (37)ipumaqar
avatar (51)tanliorsPeri
avatar (43)lapedDow
avatar (49)rituabew
avatar (37)omyjul
avatar (41)papedDow
avatar (50)ArnoldFum
avatar (38)yfaza
avatar (49)Kevensi
avatar (48)ConradRoand
avatar (39)boineDon
avatar (51)spoofTum
avatar (50)WillieVot
avatar (40)Grompelbawn
avatar (41)vkseogaF
avatar (37)usogy
avatar (40)ywixazok
avatar (38)ixoqe
avatar (56)Step 1
avatar (36)pa.OpenTran

[-]
Online Staff
There are no staff members currently online.

>