Google Chrome Extensions Hide Malice

Researchers from ICEBEG found malicious code hiding in four popular Google Chrome extensions. The search giant is working to fix the problem.

Larry Loeb, Blogger, Informationweek

January 17, 2018

3 Min Read

Google Chrome is the most popular web browser, and four extensions that can inject malicious code into it have been found hiding in plain sight on the Chrome Web Store.

ICEBRG, a US-based security firm, first noticed a problem that included an unusual amount of traffic emulating from a workstation to a European virtual private server (VPS) provider. This caused researchers to dig further, and issue a report on the situation.

What researchers found was a Chrome extension named "Change HTTP Request Header," which could download obfuscated JSON files from the "change-request[.]info" website -- IP address of 109.206.161[.]14 -- via an "update_presets()" function.

The malicious extension at work\r\n(Source: ICEBERG)\r\n

The malicious extension at work
\r\n(Source: ICEBERG)\r\n

Now, Chrome can execute JavaScript code contained within JSON but it's not supposed to be able to do so without explicit permission. The extension snuck in a change in permissions to the browser before the JSON was downloaded and then executed.

The downloaded code was observed by ICEBRG to check for Chrome debugging tools and then halting the execution of the infected segment if those tools were found.

When active, the extension would create a WebSocket tunnel to the command and control server and establish proxy browsing traffic via the victim's browser. It then causes the affected systems to land on advertising sites to which referring sites are paid a "pay per click" bounty. The technique used to make this happen could be used for other malicious actions, however. Browsing the internal network of a victim and bypassing perimeter controls would be one situation that could be easily constructed by use of the same method.

Other Chrome extensions were found to use these same techniques. Specifically, Nyoogle-Custom Logo for Google, Lite Bookmarks and Stickies -- Chrome's Post-it Notes. All of these extensions had a reach of about 500,000 users.

Even though three out of the four extensions had been removed from the Chrome Web Store -- Nyoogle still remains -- they may remain active for unaware users in their browsers.

ICEBRG researchers note that they have notified the relevant parties to "coordinate responses," including the National Cyber Security Centre of The Netherlands (NCSC-NL), the United States Computer Emergency Readiness Team (US-CERT) and the Google Safe Browsing Operations team.

Google seems to be trying to increase extension security on Chrome by limiting code injection of any kind but that may not be practical for all types of software functions.

Google itself will have to come up with a better control mechanism than it currently shows now in order to be a truly enterprise-class browser that cannot be easily fooled.

Related posts:

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Read more about:

Security Now

About the Author

Larry Loeb

Blogger, Informationweek

Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek. He has written a book on the Secure Electronic Transaction Internet protocol. His latest book has the commercially obligatory title of Hack Proofing XML. He's been online since uucp "bang" addressing (where the world existed relative to !decvax), serving as editor of the Macintosh Exchange on BIX and the VARBusiness Exchange. His first Mac had 128 KB of memory, which was a big step up from his first 1130, which had 4 KB, as did his first 1401. You can e-mail him at [email protected].

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights