Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Google Follows Microsoft to Remove ModHeader Extension from Store Following Reports of Covert Exfiltration Capability

Дата публикации: 14-07-2026 10:23:36

Google and Microsoft have removed ModHeader, a widely used developer tool for editing HTTP headers, after security researchers discovered a dormant data-collection mechanism built directly into its genuine, signed store version. ModHeader had amassed approximately 1.6 million installs across the two browsers before its takedown. Hidden Collector Found Inside the Official Build The discovery came […]

Основное содержимое страницы с новостью.

Chrome Browser Open on a Laptop Placed on a Desk

  • Extensions Pulled: Google removed the ModHeader browser extension after a dormant data collector was found hidden inside its official store build.

  • Install Base: ModHeader had roughly 1.6 million installs combined across Chrome and Edge before removal.

  • Store Removal: The extension was pulled from both the Chrome Web Store and the Microsoft Edge Add-ons store within about a week of each other.

Google and Microsoft have removed ModHeader, a widely used developer tool for editing HTTP headers, after security researchers discovered a dormant data-collection mechanism built directly into its genuine, signed store version. ModHeader had amassed approximately 1.6 million installs across the two browsers before its takedown.

The discovery came from Stripe OLT, a U.K.-based security firm, which verified the code against Google's own Web Store signature and confirmed the collector shipped inside the authentic extension rather than a counterfeit copy. 

The report was updated on July 13 with Google’s announcement that it pulled the Chrome listing on July 10, a week after Microsoft removed the Edge listing on July 3, 2026. 

The collector itself was inactive: an empty allow-list kept it switched off, and no evidence has surfaced that it ever gathered or transmitted browsing data. 

However, the underlying pipeline, including the endpoint, encryption key, scheduler, storage, and collection logic, was fully built and could have been activated through a routine extension update. A future “update” could have activated it without any new permissions or user interaction.

What the Extension Was Actually Doing

Separately, researchers found the extension was logging product, version identifier, and browser type, and pinging an external domain with product and version details each time it was installed, updated, or uninstalled. 

Because ModHeader is designed to give broad access to a browser's traffic for legitimate testing and debugging purposes, that same access made it a high-value target once trust in the codebase was compromised.

Some sources allege the extension uses a fake "Stanford Studies" front for the exfiltration domain, and weak signals point to a Chinese-speaking operator.

Marketplace Response and Ongoing Exposure

Removing ModHeader from both the Chrome Web Store and the Microsoft Edge Add-ons store prevents new installs but does not delete the extension from devices where it's already installed. 

Affected users are advised to manually check their Chrome and Edge extensions list and remove ModHeader if it remains active.

The report also notes that the infrastructure here, which debuted in 2024, shares several characteristics with the pattern Brian Krebs described in a 2021 report on popular browser extensions quietly bought” and repurposed into monetization and surveillance channels.

In late June, Microsoft removed 100+ StegoAd Edge extensions hiding malware via steganography.


Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Фальшивое расширение Perplexity перехватывало трафик пользователей0802-07-2026
2FT: эксперты Google обнаружили уязвимости в браузере Safari0023-01-2020
3Adobe-Chrome-Erweiterung ermöglichte Datenklau02524-07-2026
4Популярный блокировщик рекламы для Chrome может выполнять произвольный код-2826-06-2026
5Microsoft Cancels AI-Powered History Search Feature in Edge After User Backlash0529-06-2026
6Malicious AI Coding Plugins Hit JetBrains Marketplace, Stealing API Keys From Developers-2817-06-2026
7Google is locking out third-party apps, it does not affect de-Googled Android0506-07-2026
8Роскомнадзор разблокировал более 130 тысяч IP-адресов подсети Microsoft0023-01-2019
9Urgent warning to iPhone users over 'sophisticated' scam stealing financial data and texts: Act NOW-2604-03-2026
10В Microsoft заявили о кибератаках на 16 спортивных и антидопинговых организаций0029-10-2019

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7. Источник: www.technadu.com.