Browse Definitions:
Definition

browser extension malware

Contributor(s): Ivy Wigmore

Extension malware is any browser extension that was developed intentionally with coding that causes undesirable behaviors or whose code has been compromised by an attacker to do so.

Like other types of software, browser extensions can be designed to carry out attacks. In January 2018, for example, a security company called ICEBERG reported that they had detected four malicious extensions available from the Chrome Web Store. The four -- Change HTTP Request Header, Nyoogle - Custom Logo for Google, Lite Bookmarks and Stickies - Chrome's Post-it Notes -- were apparently designed to conduct click fraud and black hat SEO practices. ICEBERG warned that the same access methods that enabled those behaviors could also make it possible for the attackers to breach corporate networks and gather sensitive data.

Although Google subsequently removed the four extensions from the store, ICEBERG noted that the extensions may still exist on the machines of people who downloaded them and that they may also still be available through third-party repositories.

In other cases, an extension may be hijacked by an attacker. According to threat protection vendor Proofpoint, in July and August of 2017, eight compromised Chrome browser extensions (Copyfish, Web Developer, Chrometana, Infinity New Tab, Web Paint, Social Fixer, TouchVPN and Betternet VPN ) sent malicious code to nearly 4.8 million users. Targeted users were shown a JavaScript alert that said their PC needed to be repaired and were then directed to pay for the false repairs, enabling the attackers to profit from this scheme.

Security experts recommend that users be judicious when installing browser extensions. Whenever possible, you should check what permissions an extension requires. It’s wise, as well, to refrain from installing extensions from unknown companies and developers.

This was last updated in January 2018

Continue Reading About browser extension malware

Start the conversation

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • risk map (risk heat map)

    A risk map, also known as a risk heat map, is a data visualization tool for communicating specific risks an organization faces.

  • internal audit (IA)

    An internal audit (IA) is an organizational initiative to monitor and analyze its own business operations in order to determine ...

  • pure risk (absolute risk)

    Pure risk, also called absolute risk, is a category of threat that is beyond human control and has only one possible outcome if ...

SearchSecurity

  • FIDO (Fast Identity Online)

    FIDO (Fast ID Online) is a set of technology-agnostic security specifications for strong authentication. FIDO is developed by the...

  • cryptanalysis

    Cryptanalysis is the study of ciphertext, ciphers and cryptosystems with the aim of understanding how they work and finding and ...

  • Trojan horse (computing)

    In computing, a Trojan horse is a program that appears harmless, but is, in fact, malicious.

SearchHealthIT

SearchDisasterRecovery

  • business continuity and disaster recovery (BCDR)

    Business continuity and disaster recovery (BCDR) are closely related practices that describe an organization's preparation for ...

  • business continuity plan (BCP)

    A business continuity plan (BCP) is a document that consists of the critical information an organization needs to continue ...

  • call tree

    A call tree -- sometimes referred to as a phone tree -- is a telecommunications chain for notifying specific individuals of an ...

SearchStorage

  • cloud SLA (cloud service-level agreement)

    A cloud SLA (cloud service-level agreement) is an agreement between a cloud service provider and a customer that ensures a ...

  • wear leveling

    Wear leveling is a process that is designed to extend the life of solid-state storage devices.

  • storage area network (SAN)

    A storage area network (SAN) is a dedicated high-speed network or subnetwork that interconnects and presents shared pools of ...

SearchSolidStateStorage

  • hybrid hard disk drive (HDD)

    A hybrid hard disk drive is an electromechanical spinning hard disk that contains some amount of NAND Flash memory.

Close