Chrome, Safari, Opera, Firefox, Microsoft Edge, and Internet Explorer are some of the famous web browsers that allow extensions. As a result, many people end up using them. Because of the large user base, bad actors are attracted to package malicious extensions. But, browser extensions require a number of access permissions to function, including things like browser history, web content, and even login credentials. Because extensions aren’t apps – they operate within web browsers – antivirus software isn’t always able to detect harmful extensions.
Some malicious extensions carry out man-in-the-browser attacks, a type of man-in-the-middle attack that misleads browser content in order to steal sensitive personal information or lead victims into malware-infected websites. Some malicious extensions imitate the top chrome extensions that are popular for providing online security which end up misleading general users.
Table of Contents
What Can Go Wrong With Extensions?
Malicious Extensions
To start with, extensions can be simply malicious. This is most common with extensions from third-party websites, but malware can even infect authorized markets, like in the case of Android and Google Play.
For example, security experts recently discovered four extensions in the Google Chrome Web Store that tried to portray as simple sticky notes apps while secretly clicking on pay-per-click advertising to generate revenues for their developers.
How is it possible for an extension to perform anything like that? An extension requires permissions in order to function. The problem is that only Google Chrome prompts users to grant these permissions (or not); other browsers enable extensions to do whatever they want by default, and the user has no choice but to accept it.
However, even in Chrome, rights management exists only in theory — it does not operate in practice. Even the most basic extensions usually require permission to “read and update all your data on the websites you visit,” giving them the ability to do nearly anything with your data. And if you do not provide them that authorization, they will not be installed.
Hijacking and buying extensions
Browser extensions are an attractive target for criminals since many of them have large user bases. And they are automatically updated, which means that if a person downloads a harmless extension, it may be changed to become harmful; that update would be delivered to the user immediately — and the user would not notice anything at all.
A good developer would never do something like this, but their account might be hijacked and a malicious update posted to the main store on their behalf. That’s what happened when hackers used phishing to obtain the login credentials of the authors of Copyfish, a popular plugin. In that situation, crooks used the plugin, which was designed to do optical character recognition, to display more advertising to consumers.
Examples of malicious extensions
The following is a list of Chrome extensions that Avast claims to contain dangerous code:
- Direct Message for Instagram
- DM for Instagram
- Universal Video Downloader
- App Phone for Instagram
- Stories for Instagram
- Invisible mode for Instagram Direct Message
- Video Downloader for FaceBook™
- Vimeo™ Video Downloader
- Downloader for Instagram
- Zoomer for Instagram and Facebook
- Upload photo to Instagram™
- VK UnBlock. Works fast.
- The New York Times News
- Spotify Music Downloader
- Odnoklassniki UnBlock. Works quickly.
How to Spot Malicious Extensions?
Google removed the malicious extensions on each user’s browser, as is standard procedure. Anyone who tries to use them will now notice a “malware” label next to their name in Google Chrome’s browser extension area. The fact that so many of these add-ons were available through the Chrome Web Store.
The good news is that harmful browser extensions may be detected before they enter your browser. What you can do is as follows:
Look up the developer’s profile.
It is usual for extension developers to have a website or a public profile where their identity may be verified. Check that the name listed on the extension resembles the name of the developer. If you are still unsure, go to the developer’s website and install the extension there rather than searching through the extension marketplace’s overloaded listings to discover your preferred extension (which may have been published by a fake developer with some changes).
Keep an eye on your browser’s activity
Keep an eye out for anything out of the ordinary when utilizing browser extensions. Check which extensions are running if your web browser mysteriously displays plenty of ads. You can then disable and reactivate them one at a time to find the faulty extension.
Aside from that, you should never download a large number of extensions all at once. It slows down the browser and puts a burden on the RAM of your computer.
Read the permissions that extensions require carefully
If an extension requests permissions that look out of the ordinary, it’s helpful to read the extension’s description again. This allows you to determine whether they are compatible with the app’s functionality. A screenshot extension, for example, should not require permission to access a person’s email. In a nutshell, if you can’t come up with a reasonable purpose for the permissions the extension asks for, you’re most likely dealing with a malicious browser extension.
How can Chrome Help You in Identifying Malicious Extensions?
Google Chrome’s Enhanced Safe Browsing feature is easily enabled by going to the browser’s security settings, where you’ll discover three different degrees of protection.
To start, navigate to “Settings” in the top-right corner of the browser, and then pick “Security” under “Privacy and security.” You will then be able to choose a degree of protection, which comprises Enhanced Safe Browsing.
Users can also select “Standard protection,” which will still provide warnings about unsafe downloads, but you can also choose to receive warnings about password breaches and provide Google security information. If you don’t want any of that, you can choose for no protection.
Conclusion
Browser extensions make our life easier, but not all of them are made equal, and some are more harmful than beneficial. As a result, you should use extreme caution when installing an extension. Before you start installing it, look into its history and publisher. Also, keep an eye on your downloaded extensions and remove any that aren’t in use. It’s also a good idea to look through browser forums to see whether anyone else has reported about the extension you intend to install.
By following these steps, you should be able to detect a malicious extension before it has a chance to steal your personal information.
