Google Chrome: legit EditThisCookie extension removed instead of malicious copycat
#1
Exclamation 
Quote:EditThisCookie is a specialized extension for Google Chrome that you may use to edit cookie data stored by the browser. I mentioned it back in 2015 here on Ghacks.

The extension, with over 3 million users and 11,000 ratings, has been removed from the Chrome Web Store. What Google has not removed is a copycat extension, first called EditThisCookies and now EditThisCookie®, which is malicious.

When you try to launch the Chrome Web Store address of the legitimate extension, you get the "This item is not available" error message. The page of the fake extension is still up (not linked, because it is malicious).

Eric Parker, known for his malware investigations, analyzed the malicious extension in a YouTube video.

The extension had 30,000 users at the time the video was published on YouTube. Today, it sits at more than 50,000 users.

Parker installed the extension on a test system and discovered several anomalies. These include:
  • A fake website for the fake extension.
  • Obfuscated code.
  • Information stealing code, especially when on Facebook.
  • Phishing.
  • Advertising code.
The researcher did not find code to exfiltrate cookie data, which means that session cookies are not touched by the analyzed version of the extension.

With automatic extension updates enabled by default in Chrome, there is a chance that additional spyware or malware capabilities are added via updates.

Contnue Reading...
Reply


Messages In This Thread
Google Chrome: legit EditThisCookie extension removed instead of malicious copycat - by harlan4096 - 31 December 24, 09:05

Forum Jump:


Users browsing this thread:
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
VeraCrypt developer claims that Microso...
Microsoft Account Te...harlan4096 — 10:57
Surfshark VPN : Award-winning VPN servi...
How can generative...jasonX — 09:58
Surfshark VPN : Award-winning VPN servi...
What is post-quant...jasonX — 09:50
Adobe Acrobat Reader DC 2026.001.21411
Adobe Acrobat Read...harlan4096 — 09:47
Acronis True Image 2021 Build 32010
It's been a while si...jasonX — 09:27

[-]
Birthdays
Today's Birthdays
avatar (46)Rodneykak
avatar (49)tradeSmode
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo
avatar (38)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>