Another day, another Google cull: Chocolate Factory axes 49 malicious Chrome extensions from web store
- Reference: 1586934072
- News link: https://www.theregister.co.uk/2020/04/15/google_malicious_chrome/
- Source link:
The latest set of bad browser add-ons, identified by researchers from security shop [1]MyCrypto and [2]PhishFort , targeted cryptocurrency services and users in an effort to gain access to digital funds.
"Essentially, the extensions are phishing for secrets – mnemonic phrases, private keys, and keystore files," explained Harry Denley, director of security at MyCrypto, on Tuesday in a [3]blog post . "Once the user has entered them, the extension sends an HTTP POST request to its backend, where the bad actors receive the secrets and empty the accounts."
Denley said the extension set – which took aim at services like Ledger, Trezoe, Jaxx, Electrum, MyEtherWallet, MetaMask, Exodus, and KeyKeep – was associated with 14 command-and-control servers that are believed to be linked to the same person or group, possibly in Russia.
A video of the MEW CW (MyEtherWallet) extension shows how it listens for secrets entered into the browser and sends them out over the network to the malware author.
According to Denley, a few of the command-and-control servers were old but 80 per cent of them are associated with domains registered in March or April. The extensions themselves began to show up in February, with most arriving in the next two months.
Some of the extensions, he said, were supported by fake five-star reviews; some internet good samaritans also tried to warn others that the extensions were malicious. >Google did not immediately respond to a request for comment but the 49 extensions identified by MyCrypto and PhishFort are no longer available in the Chrome Web Store.
Google tests hiding Chrome extension icons by default, developers definitely not amused by the change [4]READ MORE
About two million people currently use extensions from the Chrome Web Store, according to a report earlier this month from Extension Monitor. Last month, the store had 213,054 extensions, up 3,468 from February.
That same month, Google confirmed a significant Chrome extension purge, amounting to [5]about 500 extensions . In January, Google briefly [6]halted the publication of any new extensions because of a fraud surge.
Chrome extension security has been an issue since before the Chrome Web Store launched in December 2010. Recall [7]our report on a Chrome extension trojan from April 2010.
Coincidentally, Google pushed for Chrome extension security improvements in [8]2011 , [9]2012 , [10]2013 , [11]2014 , [12]2015 , [13]2016 , [14]2017 , [15]2018 , and [16]2019 . It's still doing so.
[17]Its most recent effort involves retooling its extension APIs to make them less powerful, a project dubbed Manifest v3. This should limit abuse but it's also likely to hinder legitimate developers trying to implement content blocking and privacy features that rely on intercepting and rewriting network traffic. ®
Sponsored: [18]How To Accelerate Brilliant Digital Experiences With Low-Code
[1] https://beta.mycrypto.com/
[2] https://beta.mycrypto.com/
[3] https://medium.com/mycrypto/discovering-fake-browser-extensions-that-target-users-of-ledger-trezor-mew-metamask-and-more-e281a2b80ff9
[4] https://www.theregister.co.uk/2020/04/07/chrome_hiding_extensions/
[5] https://www.theregister.co.uk/2020/02/14/500_chrome_extensions_removed/
[6] https://www.theregister.co.uk/2020/01/27/google_disables_web_store/
[7] https://www.theregister.co.uk/2010/04/19/google_chrome_trojan/
[8] https://blog.chromium.org/2011/07/writing-extensions-more-securely.html
[9] https://blog.chromium.org/2012/12/no-more-silent-extension-installs.html
[10] https://blog.chromium.org/2013/11/protecting-windows-users-from-malicious.html
[11] https://chrome.googleblog.com/2014/05/protecting-chrome-users-from-malicious.html
[12] https://blog.chromium.org/2015/05/continuing-to-protect-chrome-users-from.html
[13] https://blog.chromium.org/2016/04/ensuring-transparency-and-choice-in.html
[14] https://blog.chromium.org/2017/05/improving-extension-security-with-out.html
[15] https://blog.chromium.org/2018/10/trustworthy-chrome-extensions-by-default.html
[16] https://blog.chromium.org/2019/06/web-request-and-declarative-net-request.html
[17] https://www.theregister.co.uk/2019/06/17/chrome_extensions_security/
[18] https://go.theregister.co.uk/tl/1936/-8552/how-to-accelerate-brilliant-digital-experiences-with-low-code?td=wptl1936
Apple's review procedures remind me of the security gates at Disney World or Universal. At first glance the bag search appears to be there to stop people bringing weapons into the park which it legitimately might do on occasion. But their main purpose is to stop people bringing their own food or drink in and depriving the park of revenue. Same for Apple.
Apple don't review the app's source code, it reviews the binary and subjects it to a test. If it passes the test it is accepted. Given that an app could be hundreds of thousands of lines of code it would be relatively trivial to hide something that passes this test and still does something malicious in the future.
Likewise with extensions. Anything malicious could be obfuscated. It would be better to monitor the behaviour of the extension in the wild, or a simulated wilderness and see what it does.
Just a naive idea
Surely apps should have a limited set of domains they can talk to, set up in some manifest. Then if they happen to whisper secrets elsewhere there's an immediate gatekeeper violation.
Duh, why doesn't Google check the extensions before letting them into the store?
Ditto the Android Play store.
I'm not a huge Apple fan, but this is one thing Apple have done well.