Hidden spy for 1.6 million users. Popular browser expansion secretly collected the history of visits

A popular browser extension can for years preserve the reputation of a secure tool while there is already a ready-made tracking mechanism inside. Google and Microsoft have removed ModHeader from Chrome and Edge stores after detecting a hidden builder of visits in the official version of the extension with approximately 1.6 million units.

ModHeader allows you to change the HTTP headers that the browser and the site are exchanged when downloading pages. The tool is used by developers and testing specialists to replace query parameters, check the work of sites and add authorization tokens without changing the program code.

Specialists of the British company Stripe OLT checked the code on the signature of the Chrome Web Store and подтвердилиconfirmed that the suspicious module was included in the real assembly, and not in the fake. Microsoft removed the extension from Edge on July 3, Google removed the version for Chrome on July 10.

ModHeader continued to perform the claimed functions, but the background code contained a separate data collection mechanism. When started, the extension formed an imprint of the device, retrieved the domains of open pages, encrypted them and could store up to 1000 addresses. Once a day, the list was to be sent to api.stanfordstudies[.com along with the print of the device, after which the local copy was deleted.
The collector remained inactive, because it was launched only for browsers from the internal list, and the list was delivered empty. No evidence of collecting or conveying the history of visits was found by specialists. However, to enable the mechanism, the developer would have had to do the usual update without requesting new permissions and actions on the part of the user.

Part of the telemetry was already working. When installing, updating and removing, ModHeader sent product information, the product, version and browser to extensions-hub[.]com. The script on each page also retained query metadata in the open form. At the same time, the automatic services evaluated the risk associated with the expansion as low, since the transmission of the story was disabled, the data was encrypted, and the code was hidden inside a legitimate project.

Users are advised to remove ModHeader from Chrome and Edge and check if the extension will return the extension to the profile synchronization or corporate policy. Those who have entered APIs, access tokens or session cookies through the ModHeader should be replaced. Administrators are advised to block stanfordstudis[.]com and extensions-hub[.com, as well as check logs for access to these domains and extension identifiers.
 
Top Bottom