Two malicious Google Chrome extensions with the same name and uploaded by the same developer have been found by cybersecurity researchers. These extensions have the ability to intercept communications and obtain user passwords.
The extensions are marketed as a “multi-location network speed test plug-in” for foreign trade staff and developers. As of this writing, you can download both browser add-ons. The extensions’ specifics are as follows:
- Phantom Shuttle (ID: fbfldogmkadejddihifklefknmikncaj) – 2,000 users (Published on November 26, 2017)
- Phantom Shuttle (ID: ocpcmfmiidofonkbodpdhgddhlcmcofd) – 180 users (Published on April 27, 2023)
According to Socket security researcher Kush Pandya, users pay subscriptions ranging from ¥9.9 to ¥95.9 CNY ($1.40 to $13.50 USD), thinking they are buying a genuine VPN service, but both variations carry out the same fraudulent operations.
The extensions function as man-in-the-middle proxies, carry out full traffic interception via authentication credential injection, and continually exfiltrate user data read more about Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
