Browse Definitions :
Definition

browser extension malware

Contributor(s): Ivy Wigmore

Extension malware is any browser extension that was developed intentionally with coding that causes undesirable behaviors or whose code has been compromised by an attacker to do so.

Like other types of software, browser extensions can be designed to carry out attacks. In January 2018, for example, a security company called ICEBERG reported that they had detected four malicious extensions available from the Chrome Web Store. The four -- Change HTTP Request Header, Nyoogle - Custom Logo for Google, Lite Bookmarks and Stickies - Chrome's Post-it Notes -- were apparently designed to conduct click fraud and black hat SEO practices. ICEBERG warned that the same access methods that enabled those behaviors could also make it possible for the attackers to breach corporate networks and gather sensitive data.

Although Google subsequently removed the four extensions from the store, ICEBERG noted that the extensions may still exist on the machines of people who downloaded them and that they may also still be available through third-party repositories.

In other cases, an extension may be hijacked by an attacker. According to threat protection vendor Proofpoint, in July and August of 2017, eight compromised Chrome browser extensions (Copyfish, Web Developer, Chrometana, Infinity New Tab, Web Paint, Social Fixer, TouchVPN and Betternet VPN ) sent malicious code to nearly 4.8 million users. Targeted users were shown a JavaScript alert that said their PC needed to be repaired and were then directed to pay for the false repairs, enabling the attackers to profit from this scheme.

Security experts recommend that users be judicious when installing browser extensions. Whenever possible, you should check what permissions an extension requires. It’s wise, as well, to refrain from installing extensions from unknown companies and developers.

This was last updated in January 2018

Continue Reading About browser extension malware

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • PCI DSS (Payment Card Industry Data Security Standard)

    The Payment Card Industry Data Security Standard (PCI DSS) is a widely accepted set of policies and procedures intended to ...

  • risk management

    Risk management is the process of identifying, assessing and controlling threats to an organization's capital and earnings.

  • compliance framework

    A compliance framework is a structured set of guidelines that details an organization's processes for maintaining accordance with...

SearchSecurity

  • Trojan horse (computing)

    In computing, a Trojan horse is a program downloaded and installed on a computer that appears harmless, but is, in fact, ...

  • identity theft

    Identity theft, also known as identity fraud, is a crime in which an imposter obtains key pieces of personally identifiable ...

  • DNS over HTTPS (DoH)

    DNS over HTTPS (DoH) is a relatively new protocol that encrypts domain name system traffic by passing DNS queries through a ...

SearchHealthIT

  • telemedicine (telehealth)

    Telemedicine is the remote delivery of healthcare services, such as health assessments or consultations, over the ...

  • Project Nightingale

    Project Nightingale is a controversial partnership between Google and Ascension, the second largest health system in the United ...

  • medical practice management (MPM) software

    Medical practice management (MPM) software is a collection of computerized services used by healthcare professionals and ...

SearchDisasterRecovery

SearchStorage

  • M.2 SSD

    An M.2 SSD is a solid-state drive (SSD) that conforms to a computer industry specification and is used in internally mounted ...

  • kilobyte (KB or Kbyte)

    A kilobyte (KB or Kbyte) is a unit of measurement for computer memory or data storage used by mathematics and computer science ...

  • virtual memory

    Virtual memory is a memory management capability of an operating system (OS) that uses hardware and software to allow a computer ...

Close