Malicious Chrome Extension Impacts Over 1M Users

Chris Pederick, the creator of the Chrome extension Web Developer, was recently phished.  The cyber criminals effectively breached Pederick’s Google account, which was tied to the app.  Therefore, the cyber criminals were able to access the app and make any changes they wanted.  After doing just that, the hackers pushed out a new “updated version” of Web Developer.  It is believed, most of the changes included the ability to distribute spam ads to different webpages users visit.  Beyond spamming users, additional concerns have been raised as well.  Express reported,

“…the Chrome plugin has access to almost everything that takes place within users’ web browser – enabling the malware-ridden software to read website content, intercept traffic, record keystrokes, and more.”

The malicious update was available for six hours before it was pulled from the Chrome Web Store.  Since, Pederick has fixed the issue, and has released an updated version of the app.  Therefore, all users of Web Developer are advised to update to the 0.5 version immediately.

20 thoughts on "Malicious Chrome Extension Impacts Over 1M Users"

  1. I’ve never had anything to do with Google!! I use Bing for any look ups. I just downloaded
    a new browser called “Honey” to get the best prices on amazon, ebay and many others. During the download Honey kept trying to down load Chrome? I did not! Anytime an email with a link to some exciting thing or to I always just place the cursor offer the link and at the bottom you always get a different link. Just delete those phishing mails.

  3. I recently did a search for “weather underground” using chrome. The next thing I know an extension downloads and my browser looks completely different. Is this potentially malicious? Haven’t seen anything unusual show up yet but I’m concerned that something downloads like that without my wanting it to.

  4. I just recently change over to chrome, due to problems with edge. I have experienced my email blowing up with nasty unwanted emails for about a week now ! Not being very good on computer, this has been frustrating for me….
    I have pc matic for protection etc. but I’m still receiving these emails ???

    1. Mia, PC Matic does not include email filtering. If anything malicious tried to execute on your machine from those emails PC Matic would stop it, but we do not have access to your email provider to block messages from your inbox.

  5. I have to wonder if anything is safe. Even Firefox can become tainted. Whatever anyone does online is meat for the grill of evil people. And there are uncounted millions of such people.
    The internet has been great, but humanity isn’t grown up enough to use it constructively. Most humans are thieves, of one kind or another. Nothing, not even religion, can make a thief desist.
    This is knowledge I’ve had for years. It is why I never transact financial things online. I never use social media of any kind. I never give out my phone number or address.
    YEARS ago, we all were told that anything you put online can stay there forever. It’s like the old saw about never writing something you wouldn’t want to appear in the newspapers. Actually, when things like this happen online, the results are much worse.
    1. @Holly Bergeim: Some states routinely sell voter registration lists to telemarketers. A practice I abhor but can do nothing about. My question is, if they are selling voter info to the highest bidder, how can they justify denial of same to a federal investigation?

  7. You can’t rely either on Google doing anything about a malicious Chrome extension, despite having acquired it from their own official Chrome webstore.

    Installing the FullTab Chrome Extension ( subjected my pc to a browser hijack that took me two days to remove & I am still coping with the damage that this harmful extension has caused – it’s disguised adware that initiates redirects & causes popups via

    Yet reporting this to Google not just once but several times via different routes has been met with nothing more than silence on their part.

    The message to me is clear – you can’t trust Google Chrome.

    1. @Logomage:

      I never want chrome on my pc but it is very hard to escape the multitude of ads harassing me to get it now to save my pc from attack!

      mmmm….. I wonder why I dislike it so much?

  8. Bryan Lancaster

    A not too dissimilar thing happened a few weeks/month ago with Social Fixer in the Chrome Web Store.

