Another cluster of potentially malicious Chrome extensions
palant.info
palant.info
a) I was surprised that they don't require access to the source code in order to review. I wrote everything using typescript and uploaded the packed/obfuscated output, which wasn't a problem at all. I'm sure they have software that unpacks and attempts to detect hazardous patterns, but clearly humans are not actually trying to understand the code's structure. It would be a low bar to require well commented source code (and even to require certain coding conventions) to make extension code more reviewable. Want to be on our platform? Write it this way. Show us the source.
b) On the flip side, trying to do anything interesting requires adding permission after permission to the manifest, which of course results in the scary messaging at install time. While you're asked to justify each permission when you upload, as far as I'm aware extension authors have to provide their own copy to end users attempting to explain permissions - I've certainly never seen it as an end user when installing an extension. Including these explanations either in the initial install dialog, or on first usage of each permission, would be beneficial. Of course this would require that extension reviewers verify the usage of each of the permissions, but since they're universally accessed through the chrome api, they should be easy to spot in the source (and #a would help this significantly).
Yes, Mozilla doesn’t publish the source code. Back when I was reviewing add-ons there (a long time ago), I did compile the supplied source and compared it with the submitted one. It was sometimes awkward when the tool in question didn’t produce reproducible builds but mostly ok.
Unfortunately Google believes their scale means having a human involved in anything is unacceptable, which is why the Chrome Web Store will eternally be the leading source of malware for computers.
Yeah, I mean they've had a solid 14 years to give it a fair shot, and have evidently failed. Browser authors are unhappy, moderately technical users are suspicious, and unaware users can get taken advantage of.
Even a moderate pay-per-review fee would be a cut above the current situatioin.
The boring truth is that automation or not, it's difficult. Manifest v3 in some aspects improves the situation (but it's not that great).
It would certainly be more trustworthy if they'd add identity verification. eIDAS makes it low-cost to implement in the EU. At least it'd require a new malicious company or person willing to taint their name to continue operations.
Any indie extension that has an audience could get a donor base, but yeah - smaller first-time extensions that only underwent automated review could either fly unlisted / or with a non-"blue-star", or even with an "unverified" banner. The small fee could make looping humans into the loop relatively revenue neutral, and increase the chance of detection of stuff like this. The more misses by the automated system, the more the platform suffers, and the less chance any of us have of getting users.
I'm curious if any security software could detect malicious chrome extensions on the Chromestore. That'd be helpful.
Scanning of the binaries, "Notarization", Developer ID signing and all that stuff is something different.
BTW, I checked out the video in your bio a couple of days ago, absolutely fantastic! Thanks for the recommendation.
I was confused as after buying the guy seemingly did nothing with the extension. Now I'm realizing that it has become a part of the malware community. I was also using ESCompiler to bundle files which was naturally obfuscating it a lot.
The point is that these people acquire extensions when they have a growth trajectory, then sit back and let the cash roll in. Kinda like VCs. That's why they have such a huge collection of popular extensions.
Also, To get "Featured" on chrome, you just have to fill a paltry form about accessibility etc and wait for a few weeks. "Featured" does not mean the application is safe in any way. I'd say it's the contrary since the scammers know exactly how to get the tag to look more trustworthy.
> I was confused as after buying the guy seemingly did nothing with the extension.
This is a surprised_pikachu.png moment. Did you honestly expect someone paying $600 to maintain an extension?
Yes, Chrome uses Safe Browsing to flag malicious extensions. But they seem to use it very sparingly for some reason.
As always, if you're not the customer, you're the product.
1) My password manager extension, 2) EFF's Privacy Badger, 3) Vimium
Everything else I run only temporarily or with the option where I have to click to enable it for certain sites.
https://www.wired.com/story/lastpass-engineer-breach-securit...
Last pass wasn’t malicious, just incompetent. There is nothing to suggest that their extension is going to be secret malware.
At the same time if you have an extension that shows some status via the pinned icon you have to guide them step by step.
If an extension doesn't steal your data, then leave them be. If you don't do your homework, well, then live with the "bloodsucker mosquito". We don't have to protect everyone from the real world at the expense of the many.
I have no idea what it takes to get “featured” but having seen how pretty much any extension gets this tag, including plenty of malicious ones – it’s pretty meaningless.
I’m fairly certain that these users didn’t leave it at reviews. There is a “Report abuse” form which one can use and which was certainly used here. If only someone were actually looking at these submissions…