HNHacker News
TopNewBestAskShowJobs

toborrm9

12 karma · joined February 6, 2026

submissionscomments
toborrm9··on [dead]
Malicious Chrome extensions don't always get removed from the Web Store right away and I couldn't find a maintained list of malicious ones so I built this open source tool!

GitHub: https://github.com/toborrm9/malicious_extension_sentry Extension: https://chromewebstore.google.com/detail/malext-sentry/bpohi...

toborrm9··on Show HN: Daily-updated database of malicious browser extensions
Yes i'm working on it
toborrm9··on Show HN: Daily-updated database of malicious browser extensions
Working on it :)
toborrm9··on Show HN: Daily-updated database of malicious browser extensions
Great point. The current setup is exactly what you're describing, a fully local verification with no phone-home behavior.

The CLI/GUI tools I'm building read your locally installed extensions, extract their IDs, and check them against the CSV (which you can clone/download). No data leaves your machine during the scan.

The only "central" piece is the GitHub-hosted CSV itself, which is just a static file anyone can audit, fork, or host themselves. No API calls, no telemetry, no server lookups.

You're right that this design prevents the verification tool from becoming an attack vector. Even if my repo got compromised, worst case is a bad CSV, your local scan process stays isolated.

I'm also looking at surfacing critical permissions for locally installed extensions,things like "access to all websites," "read clipboard," etc. That way users can make informed decisions about what to keep based on what's actually authorized, even if an extension isn't in the malicious database yet.

Appreciate the security-minded feedback.