Breaking Down the Chrome Web Store
extensionmonitor.com
extensionmonitor.com
My extensions were open source and had no clear path to monetization, so I can only speculate on how the purchasers planned to recoup their investments. The permissions in these extensions would allow them to inject ads or even collect credentials, etc.
Not saying that the top extension developer does this, but people are definitely making money by collecting innocuous Chrome extensions!
> The activeTab permission gives an extension temporary access to the currently active tab when the user invokes the extension - for example by clicking its browser action. Access to the tab lasts while the user is on that page, and is revoked when the user navigates away or closes the tab.
In practice users want extensions to do stuff that implicitly violates security boundaries, so I think making that stuff secure would basically require Google to build it in. Like for example, 1password naturally needs both a way to intercept entry of new passwords (to offer saving) and a way to detect password fields and type into them. Detecting a password field means you need to be able to scan the DOM and detect when the user is interacting with the field. At the point where you can do that, you can snoop on the user on an important page, activeTab or no.
If the Chrome Web Store offered straightforward ways to sell paid extensions at least then there'd be less reason to embed malware in your extension instead...
My extension (now removed due to legal threats and DMCA abuse) was originally scoped to an application's domain, and then the developer added a new domain so I had to update my extension manifest to add that domain. Doing so shut it off for every user and I had to explain how to turn it back on. Given that experience I should have just put a wildcard in the permissions instead, but I underestimated how bad Chrome's extension infrastructure would be.
It was interesting to see this strategy, they are trying to implicate people to create publisher accounts for them, verified with credit cards that cannot be traced back to them and do not look suspicious. Though the money they have offered seemed too much for the job, I guess they are also trying to hook developers and convince them to do other stuff down the road.
I do get plenty of purchase and monetization offers, some of which I have shared in a blog post [1], but this was a trick I have never encountered before.
[1] https://armin.dev/blog/2019/08/supporting-browser-extension-...
Is your reputation that good? Why not pay any random person $500 for the use of their identity for the same thing.
You could push a lot of scareware with an extension with full access to the browser.
The add-on module is available in a limited free and paid fully featured version. It is the classical freemium model, which works well for both, the extension creators and the users.
There's also:
"You can remove your Personal Data from Grammarly at any time by deleting your account as described above. However, we may keep some of your Personal Data for as long as reasonably necessary for our legitimate business interests"
But, you get the benefit of "SSL encryption".
The other features (don't save your search) just seem to make it a bad version of DuckDuckGo.
New Tab-hijacking extensions are incredibly pervasive in the Chrome Web Store, and often installed via malicious websites which use arrows and audio cues to demand a user click the "Install" button Chrome pops up in order to resume web browsing.
MapsGalaxy is another particularly pervasive malware offering: https://chrome.google.com/webstore/detail/mapsgalaxy/ijjnmdp... (Just adding this one here in case someone from Google sees this comment and can nuke both from orbit.)
[0] https://blog.malwarebytes.com/detections/rogue-searchencrypt... and any search result should give you some idea: https://duckduckgo.com/?q=search+encrypt&t=ffab&ia=web
Original comment: That "developer" is Chrome HD Themes and the extensions are themes.
Chrome HD Themes has over 6k published extensions!
Yeah, I kind of like the ability to install extensions for use cases the developer doesn't and can't think of themselves.
- The most popular category is “Productivity” accounting for ~40k extensions and 676M installs
- Google itself authors 155 extensions accounting for ~133M installs
There are in fact 10 default extensions. Will filter them out...
Though, the latest number is now ~137M installs.
If you are interested, it might be helpful to you. It's contributing to the winning "Productivity" category. It lets you see the competitors of almost any software product. Contextually. https://chrome.google.com/webstore/detail/alternative-to-by-...