Five Chrome Extensions Found Collecting User Data Discreetly: Remove Them Now!

Five Chrome extensions with 1.4 million downloads were found collecting browsing data, users’ names, and device location (country, city, county, zip code).

September 1, 2022

Researchers at McAfee have discovered five Chrome browser extensions that track users’ browsing activity. The developers of these five extensions were discreetly inserting affiliate IDs into cookies of eCommerce sites to earn affiliate income based on user purchases. Google took down the extensions after reviewing McAfee’s findings.

McAfee’s research sprung from the March 2022 discovery of a malicious version of Netflix Party, a Chrome extension designed to enable multiple Netflix users to stream content concurrently. The author of the malicious Netflix Party went to great lengths to deceive users into trusting and installing the extension through several Twitter accounts and fake reviews websites.

Besides performing the functions it was meant to do, Netflix Party redirected users to phishing sites. It also inserted affiliate IDs and modified legitimate websites to exfiltrate users’ personally identifiable (PII) data.

McAfee has now discovered four additional extensions: Netflix Party 2, FlipShope – Price Tracker Extension, Full Page Screenshot Capture – Screenshotting, and AutoBuy Flash Sales, that exhibit similar malicious behavior.

The cumulative downloads for the five malicious extensions stand at 1.4 million users, who should assume their privacy was infringed upon. The extensions’ underlying code is similar, including the type of data being collected and the fact that they have a 15-day delay before their malicious operations are triggered to avoid detection by automated analysis tools.

See More: Google Chrome Trounced by Mozilla, Safari and Microsoft Edge in Blocking Phishing SitesOpens a new window

Data collected by the extensions include referral URLs encoded in Base64, users’ names encoded in Base64, and device location (country, city, county, zip code), all of which are sent to d.langhort.com. Going by McAfee’s blog post on the subject, the authors’ intention seems to be financial gain.

However, since the extensions fulfill their intended purpose, the underlying technical deception becomes less apparent to unknowing users. ChromeOpens a new window is the market leader among web browsers, with a 65.12% market shareOpens a new window and 188,620 extensions.

Malicious Chrome Extensions

Malicious Chrome Extensions Discovered by McAfeeOpens a new window

Details of the five malicious extensions in question, now removed from the Chrome extension store, are given in the table below. So if you still have them installed in your browser, now is the time to uninstall.

Extension Name

Overt Purpose Downloads
Netflix Party Concurrent streaming

800,000

Netflix Party 2

Concurrent streaming 300,000
FlipShope – Price Tracker Extension Coupon discovers and auto application

80,000

Full Page Screenshot Capture – Screenshotting

Web page screenshots 200,000
AutoBuy Flash Sales Identify and grab offers

20,000

Let us know if you enjoyed reading this news on LinkedInOpens a new window , TwitterOpens a new window , or FacebookOpens a new window . We would love to hear from you!

MORE ON PRIVACY RISKS

Sumeet Wadhwani
Sumeet Wadhwani

Asst. Editor, Spiceworks Ziff Davis

An earnest copywriter at heart, Sumeet is what you'd call a jack of all trades, rather techs. A self-proclaimed 'half-engineer', he dropped out of Computer Engineering to answer his creative calling pertaining to all things digital. He now writes what techies engineer. As a technology editor and writer for News and Feature articles on Spiceworks (formerly Toolbox), Sumeet covers a broad range of topics from cybersecurity, cloud, AI, emerging tech innovation, hardware, semiconductors, et al. Sumeet compounds his geopolitical interests with cartophilia and antiquarianism, not to mention the economics of current world affairs. He bleeds Blue for Chelsea and Team India! To share quotes or your inputs for stories, please get in touch on sumeet_wadhwani@swzd.com
Take me to Community
Do you still have questions? Head over to the Spiceworks Community to find answers.