At first glance the extension is mostly harmless, importing a small "background.js" file and the popular javascript extension "jquery".

I thought "looks harmless enough, seems odd that it would be malicious".
The issue: the "jquery" extension here is imported locally, and its checksum doesn't match the one on CDN.
That's because it was tampered with to include code to retrieve all cookies from the user.

Even though the extension was 2 years old, the malicious developer managed to run a successful campaign and net at least 6 figures in funds from Binance, with the victims wondering for months how that could have happened.

From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share





