Experts get Google, Microsoft to pull trusted ModHeader with 1.6 million installs after finding it could harvest all…

https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-2560-80.jpg
  • Stripe OLT found ModHeader v7.0.18 carried a hidden spyware SDK, exfiltrating visited domains daily to a Chinese‑owned server and acting as adware
  • The extension had 1.6M downloads across Chrome and Edge before being pulled but installed endpoints remain at risk
  • Researchers urge defenders to identify and remove existing installations, as removal from stores does not automatically remediate compromised devices

ModHeader, a trusted Chrome and Edge browser extension with more than 1.6 million downloads, was found to be malicious, apparently sending sensitive data to a Chinese-owned server, and has since been pulled on both repositories.

Security researchers Stripe OLT revealed the news in a new report, outlining how a ModHeader build v7.0.18 carried a hidden spyware SDK.

As per Stripe OLT, the spyware collects domains users visit, encrypts the data with AES-GCP, and then sends it - once a day - to a remote server. The collector was found inactive...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more