287 Chrome Extensions Exfiltrate Browsing History From 37.4 Million Users
## Chrome Extensions Exfiltrate Browsing History
Chrome Extensions Exfiltrate Browsing History
A significant data exfiltration operation has been identified involving 287 Chrome extensions that clandestinely extract browsing history from approximately 37.4 million users globally.
The discovery affects about one percent of the global Chrome user base, indicating a substantial privacy breach impacting millions of internet users.
An automated scanning system utilizing Docker containers and a man-in-the-middle (MITM) proxy was employed to detect suspicious network activity. The system monitors outbound traffic from extensions and assesses if data transmission correlates with URL length, a critical indicator of exfiltrated browsing history.
The malicious extensions use various obfuscation techniques, such as ROT47 encoding and AES-256 encryption with RSA key pairs, to conceal their activities and encrypt browsing data before transmitting it to remote servers.
The discovery affects about one percent of the global Chrome user base, indicating a substantial privacy breach impacting millions of internet users.
"Poper Blocker," "Stylish," and "BlockSite" were identified among the extensions involved in data exfiltration. Several data brokers were found to be collecting user information, including Similarweb, which operates multiple extensions such as the "Website Traffic & SEO Checker," affecting one million users. Big Star Labs, potentially associated with Similarweb, controls extensions impacting 3.7 million users. Other entities include Curly Doggo with 1.2 million affected users, Offidocs with 1.7 million users, and various Chinese organizations. Even legitimate security tools like Avast Online Security, with six million installations, were flagged for data collection.
The exfiltrated browsing data presents significant risks beyond targeted advertising. Corporate espionage becomes feasible when employees install seemingly benign productivity extensions that capture internal URLs, intranet addresses, and SaaS dashboard links. URLs often contain personal identifiers, facilitating targeted attacks on specific individuals.
Researchers established honeypot traps and identified third-party scrapers actively collecting the stolen data. Multiple IP addresses associated with companies like Kontera accessed these honeypots, suggesting a broader ecosystem monetizing user browsing histories.
Users should review installed Chrome extensions and remove any identified in the research report. With approximately 240,000 extensions on the Chrome Web Store, manual verification is challenging. Security experts recommend installing only open-source extensions that can be independently reviewed and carefully checking permission requests before installation.
The research team has deliberately withheld specific technical details to prevent attackers from adapting their methods more rapidly.
Based on reporting by Cyber Security News.
