City
Epaper

Malware hidden in 28 Chrome, Edge extensions hits 30 lakh people

By IANS | Updated: December 17, 2020 17:00 IST

New Delhi, Dec 17 Threat Intelligence researchers from cybersecurity firm Avast have identified malware hidden in at least ...

Open in App

New Delhi, Dec 17 Threat Intelligence researchers from cybersecurity firm Avast have identified malware hidden in at least 28 third-party Google Chrome and Microsoft Edge extensions that may have affected 30 lakh users worldwide.

The Chrome and Edge extensions are associated with some of the world's most popular platforms like Instagram, Facebook and Google Chrome.

The malware has the functionality to redirect user's traffic to ads or phishing sites and to steal people's personal data, such as birth dates, email addresses, and active devices.

According to the app stores' download numbers, around 30 lakh people may be affected worldwide.

"The extensions which aid users in downloading videos from these platforms include Video Downloader for Facebook, Vimeo Video Downloader, Instagram Story Downloader, VK Unblock, and other browser extensions on the Google Chrome Browser, and some on Microsoft Edge Browser," Avast said in a statement late on Wednesday, recommending users to disable or uninstall extensions for now.

At this moment, the infected extensions are still available for download.

Avast said it has contacted the Microsoft and Google Chrome teams to report them and the companies confirmed they are currently looking into the issue.

The researchers identified malicious code in the Javascript-based extensions that allows the extensions to download further malware onto a user's PC.

"Our hypothesis is that either the extensions were deliberately created with the malware built in, or the author waited for the extensions to become popular, and then pushed an update containing the malware," said Jan Rubin, Malware Researcher at Avast.

"It could also be that the author sold the original extensions to someone else after creating them, and then the buyer introduced the malware afterwards".

Users have also reported that these extensions are manipulating their internet experience and redirecting them to other websites.

The Avast Threat Intelligence team started monitoring this threat in November, but believe that it could have been active for years without anyone noticing.

"There are reviews on the Chrome Web Store mentioning link hijacking from as far back as December 2018," Rubin added.

( With inputs from IANS )

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

AurangabadSession of MHT-CET-PCM clashes with UPSC NDA & CDS exams

PoliticsAssam CM's wife denies Congress claims on foreign assets, calls allegations "shameful"; says party has "nothing to do except defame people"

PoliticsNCP chief Sunetra Pawar files nomination for Baramati bypoll, appeals Congress for "unopposed election"

Other SportsIndian shooters eye a strong start as mixed team events to kickstart Rifle/Pistol World Cup

BusinessIndia's strong fiscal position gives RBI more policy space: FM Sitharaman

Technology Realted Stories

TechnologyIndia’s white-collar job market ends this fiscal strong led by non‑IT, AI hiring

TechnologyIndian Railways approves Rs 1,364 crore to expand Kavach, modern signalling systems

TechnologyOver 18 crore LPG cylinders delivered since March 1, adequate rice and wheat stocks available: Govt

Technology16 Indian-flagged vessels with 433 seafarers remain in Persian Gulf: Govt

TechnologyMusk' Tesla opens 1st in-mall charging station in Navi Mumbai