A widely used browser extension, ModHeader, has been removed from online stores. Security researchers found it was secretly collecting user data. The extension had over 1.6 million installations across various platforms.
The discovery was made by Stripe OLT, a cybersecurity firm. They identified a hidden spyware component within ModHeader version 7.0.18. This component was designed to send user browsing information to an external server.
The spyware was specifically exfiltrating details about websites users visited. This sensitive information was then being sent to a third-party server. Experts believe a Chinese entity might be behind this data collection.
This type of data harvesting poses significant privacy risks. It could allow unauthorized parties to build detailed profiles of users' online activities. Such profiles could then be used for various malicious purposes.
The spyware was embedded as a Software Development Kit (SDK). This made it difficult for average users to detect its presence. The SDK operated silently in the background, continuously gathering data.
Google and Microsoft promptly removed ModHeader from their respective marketplaces. This action followed the urgent notification from security experts. The swift removal aimed to protect millions of users from further data compromise.
The incident highlights the ongoing challenges of securing browser extensions. Even trusted and popular tools can become vehicles for hidden threats. Users are advised to regularly review the permissions of their installed extensions.
The ModHeader extension was found to be collecting and sending information about the websites users visited. This included the domains of sites accessed during browsing sessions.
The spyware within ModHeader was discovered by a security research team named Stripe OLT. They identified a hidden SDK responsible for the unauthorized data collection.
Upon learning of the spyware, both Google and Microsoft removed the ModHeader extension from their official online stores. This prevented new installations and aimed to protect existing users.