Google Chrome: legit EditThisCookie extension removed instead of malicious copycat
#1
Exclamation 
Quote:EditThisCookie is a specialized extension for Google Chrome that you may use to edit cookie data stored by the browser. I mentioned it back in 2015 here on Ghacks.

The extension, with over 3 million users and 11,000 ratings, has been removed from the Chrome Web Store. What Google has not removed is a copycat extension, first called EditThisCookies and now EditThisCookie®, which is malicious.

When you try to launch the Chrome Web Store address of the legitimate extension, you get the "This item is not available" error message. The page of the fake extension is still up (not linked, because it is malicious).

Eric Parker, known for his malware investigations, analyzed the malicious extension in a YouTube video.

The extension had 30,000 users at the time the video was published on YouTube. Today, it sits at more than 50,000 users.

Parker installed the extension on a test system and discovered several anomalies. These include:
  • A fake website for the fake extension.
  • Obfuscated code.
  • Information stealing code, especially when on Facebook.
  • Phishing.
  • Advertising code.
The researcher did not find code to exfiltrate cookie data, which means that session cookies are not touched by the analyzed version of the extension.

With automatic extension updates enabled by default in Chrome, there is a chance that additional spyware or malware capabilities are added via updates.

Contnue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.1.0 / 19.1.1 Update
Changes in 19.1.1 ...harlan4096 — 07:00
Manjaro Linux 25.0.6 Build 250730
Manjaro Linux 25.0...harlan4096 — 06:57
Brave 1.80.125
Release Channel 1....harlan4096 — 06:55
Vivaldi 7.5 Build 3735.58
Vivaldi 7.5 Build ...harlan4096 — 06:54
360 Total Security 11.0.0.1217
1.0.0.1217 Jul 25,...harlan4096 — 06:53

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>