Yellow Flag
Yellow Flag

@WPalant@infosec.exchange

Wladimir Palant, software developer and security researcher, browser extensions expert. / searchable

He/him
August 21, 2018
Pinned post

Published a new article: Malicious extensions circumvent Google’s remote code ban

palant.info/2025/01/20/malicio

Looking at 60 malicious extensions belonging to three groups here, still running remote code despite Google banning it in Manifest V3. “Fun” fact: some of these extensions have been featured on my blog in 2023, others on McAfee’s in 2022.

Recurring pattern: downloading rules and adding them to declarativeNetRequest API. The abuse potential here is enormous, including injecting malicious scripts into websites.

Only one extension went for essentially a custom programming language, others settled with simpler approaches. Luckily for me because the latter allows better guesses about what this functionality is meant for. Spoiler: ads and affiliate fraud. Also: affiliate fraud and ads.

Almost Secure

Malicious extensions circumvent Google’s remote code ban

This blog post looks into how 63 malicious extensions circumvent Google’s restrictions of remote code execution in extensions. One group of extensions is associated with the company Phoenix Invicta. The other groups around Netflix Party and Sweet VPN haven’t been attributed yet.

For reference: I decided to block todon.eu and todon.nl. These servers have a long history of tolerating and encouraging antisemitism (which they call “antizionism”) while fighting people who call it out. I have to assume that whoever is still using these servers is fine with that.

Elk Logo

Welcome to Elk!

Elk is a nimble Mastodon web client. You can login to your Mastodon account and use it to interact with the fediverse.

Expect some bugs and missing features here and there. Elk is Open Source and we're actively improving it as a community project. Join us and let's build it together!

If you'd like to report a bug, help us testing, give feedback, or contribute, reach out to us on GitHub and get involved.

To boost development, you can sponsor the Team through GitHub Sponsors. We hope you enjoy Elk!

PatakDaniel RoeJoaquín Sánchez三咲智子 Kevin DengAnthony FuTAKAHASHI Shuuji

The Elk Team