Does anyone know how they get this data?
Does anyone know how they get this data?
So an extension will seem benign when it initially gets checked by Google as part of becoming part of its submission to the Chrome Store. Then, later, the external “3rd party” script that is hosted remotely will get replaced with a different, malicious script. The malicious extension carries on stealing cookies, credentials, and fingerprints until someone reverse engineers it and reports it to Google.
Google will not always recognize the issue immediately because the 3rd-party malicious code is not strictly “part of” the extension so there’s a bit of a song and dance while the person who reversed it convinces Googles reviewers that “yes, this really is actually malicious, you need to analyze the third party code that loads later” and then Google eventually takes it down after a semi-involved back-and-forth where extensive documentation and video walk-throughs are provided by the exasperated white-hat Good Samaritan.
Do you have any specifics to share ?
I’m guessing the malware is something else besides a browser extension.
let harmless = { func : function() { }, harmlessExternallyLoadedString : '' };
let toAccess = 'func';
//do stuff that seems legit
if(true) {
let toAccess = 'harmlessExternallyLoadedString';
}
harmless[toAccess] = 'alert(1);'; //imagine this being a fetch request
//later on
setTimeout(harmless.func, 1);
now imagine the logic for what othervar is set to is obfuscated a bit by a more complex logic tree, and the example was a bit less contrived.Once they get to like 100k DAU popularity level you’ll start getting emails from people who claim to want to purchase the extension from you for a few thousand or “sponsor” the development by supporting you with ads.
You either sell it, or include some JavaScript that later (few weeks) turns malicious and starts harvesting.
That’s probably how. Like I say, I have no idea if that’s how these people work, but it seems a likely attack vector.
a second way is through chrome extensions that log cookies and form data. the old cookies can be replaced with the new, stolen session via cookie editor