More than 180K Chrome users have installed ad-injecting extensions

February 4, 2014 – 4:54 PM

More than 180,000 Google Chrome users have installed at least one of a dozen ad-injecting extensions that are serving up spam on 44 different websites, according to findings by the threat and research analysis team with Barracuda Labs.

As of Jan. 30, the “logo quiz game” extension has been installed by nearly 82,000 users, and “counter strike cs portable” extension has been installed by about 27,000 users, according to a Monday post by Jason Ding, research scientist with Barracuda Labs.

Some of the more popular websites impacted by the extensions include youtube.com, yahoo.com, msn.com, imdb.com, myspace.com, and disney.go.com, Ding wrote, explaining all extensions had been served up on the Chrome Web Store directly.

“When users try to download the extensions from the Chrome Web store, it will ask for ‘Access data to all websites’ permissions before users can download and install them,” Ding said in an email to SCMagazine.com on Tuesday. “Once granted these permissions, JavaScript codes are sitting behind users’ browsers, and these extensions are available at users’ Chrome address.”

Ding then delivered the bad news. “The JavaScript code downloaded has a URL point to an outside JavaScript hosted at www.chromeadserver.com [that] will be executed whenever users are browsing a webpage,” he said.

As a result, ads are injected into the websites, sometimes filling in empty spaces on the page, Ding said, adding the JavaScript is solely for spam, only operates in Chrome browsers and does not impact other parts of the user’s system.

Source:
http://www.scmagazine.com/more-than-180k-chrome-users-have-installed-ad-injecting-extensions/article/332673/

You must be logged in to post a comment.