287 Chrome Extensions Stole History of 37.4M
A covert campaign involving 287 Chrome extensions has compromised the browsing history of approximately 37.4 million users globally, according to new research. The scale of the breach represents nearly one percent of the Chrome user base, raising privacy concerns across the internet ecosystem.
Researchers used a custom system of Docker containers and a man-in-the-middle proxy to identify suspicious outbound traffic patterns. Extensions encoded and encrypted stolen URLs using techniques like ROT47 and AES-256 with RSA key pairs, making detection more difficult.
Well-known tools such as Poper Blocker, Stylish, and BlockSite were among those flagged. Analysts traced multiple data brokers, including Similarweb and Big Star Labs, controlling extensions across millions of users. Other actors include Curly Doggo, Offidocs, and alleged Chinese-linked developers.
The 287 Chrome extensions pose threats beyond ad targeting, enabling data scraping of sensitive corporate and personal URLs. Security experts advise reviewing installed extensions and limiting permissions.
Read the full report at:
287 Chrome Extensions Exfiltrate Browsing History From 37.4 Million Users
