Malicious Chrome extensions with Session Replay appear in Chrome Store

first_imgMalicious Chrome extensions with Session Replay appear in Chrome Store by Martin Brinkmann on February 05, 2018 in Google Chrome – 15 commentsTrend Micro security researchers identified 89 different malicious extensions for Google Chrome that use Session Replay functionality to log user activity while using the browser.Session Replay scripts are analytics scripts that record user activity on websites. Companies use it to understand what users do on their sites by recording mouse movement, keyboard input and other interactions with the page in question.Research suggests that nearly 1% of the top 50,000 Alexa websites use Session Replay scripts including WordPress, Microsoft, Adobe, Godaddy or Softonic.Chrome extensions with Session Replayvia BleepingcomputerTrend Micro detected 89 different Chrome extensions with Session Replay functionality in the Chrome Web Store. All extensions that Trend Micro detected used randomized names such as Air Plant Holder, Applesauce Christmas Ornaments or Cuban Sandwich.The script records user activity and since it is browser-based and not page-based, can do so on any website the user visits. Session Replay scripts may record Credit Card numbers, addresses, bank account information, social security numbers, names, and pretty much anything else a user enters on websites.While scripts are designed not to record passwords, research showed in the past that this might happen also.All extensions have in common that they use the Session Replay script from Yandex to record user activity, and Trend Micro believes that they are operated by the same group which it named Droidclub.The company released a PDF document that lists all Chrome extensions and domains that it associates with Droidclub.Bleeping Computer reports that the extensions used command and control servers. Droidclub used the servers to inject advertising on pages visited by users, and older versions deployed the Coinhive crypto jacking script, so the site.A quick check on the Chrome Web Store revealed that all extensions on the list that I checked are no longer listed. Nearly 425,000 users installed the extensions, however.Closing WordsThe Chrome Web Store does not come to rest when it comes to malicious extensions. Google announced some time ago that it wanted to improve the security but nothing has come out of it yet.Now You: Do you vet extensions before you install them?Related articlesAnother Chrome extension horror story: coinhive and domain registrationChrome has a massive copycat extensions problemGoogle promises better protection against deceptive Chrome inline installationsGoogle pulls crypto-mining Chrome extension Archive PosterSecurity firm ICEBRG uncovers 4 malicious Chrome extensionsSummaryArticle NameMalicious Chrome extensions with Session Replay appear in Chrome StoreDescriptionTrend Micro security researchers identified 89 different malicious extensions for Google Chrome that use Session Replay functionality to log user activity while using the browser.Author Martin BrinkmannPublisher Ghacks Technology NewsLogo Advertisementlast_img read more

What an MLB source said about the Dbacks trade h

first_img What an MLB source said about the D-backs’ trade haul for Greinke Leach, 35, is a 12-year league veteran who has held downthelong-snapping job with the Cardinals since 2009. Leachwillreceive a new three-year deal. D-backs president Derrick Hall: Franchise ‘still focused on Arizona’ 0 Comments   Share   Nevada officials reach out to D-backs on potential relocation The Arizona Cardinals continued to re-sign more of theirownfree agents, according to Darren Urban ofAZCardinals.com.Cardsbring back long snapper Mike Leach (3-year contract) andLB/special teamer Reggie Walker (2-year contract).— Darren Urban (@Cardschatter) March 26,2012 Top Stories Walker, a reserve linebacker who was an undrafted freeagentout of Kansas State in 2009, played in all 16 games lastseason,primarily as a special teams member. Walker registered 16special teams tackles. He’ll receive a 2-year contract. Cardinals expect improving Murphy to contribute right awaylast_img read more