Do Not Use These Chrome ExtensionsDo you use any of the following Chrome browser extensions?

  • Change HTTP Request Header
  • Nyoogle - (a custom logo for Google)
  • Stickies - (a Post-It note for Chrome)
  • Lite Bookmarks

If so, you're not alone.  These four extensions have a combined user base of more than half a million.

Recently, security researchers from ICEBRG (a US cyber-security company) have discovered malicious codes embedded in copies of these on the official Chrome Web Store.  The code allows hackers to manipulate the users' browser via JavaScript.

So far, the hackers have only contented themselves with relatively tame activities like loading and displaying ads, clicking on ads, and loading malicious web pages in the background. However, the potential exists to do much more than this.

Since ICEBRG informed Google, the company has removed three of the four plugins from the Web Store.  As of this moment, only Nyoogle remains, though the expectation is that it will be removed in short order as well.

While all four extensions utilize the same basic techniques, and do many of the same things, it is not clear if all four were created by the same group, although this seems likely.

Since the extensions have now been (mostly) removed, the rate of infection will slow. Of course, if you've already downloaded and installed one of these four, then you are going to continue to be impacted.

The extensions are easy to uninstall, and if you're using one of them, that is the recommended course of action.

In recent months, Google has taken steps to make their auditing process more robust to prevent malicious extensions and apps from finding their way onto the web properties they manage. As this latest incident proves, no matter how careful a company is, sooner or later something is going to slip through.

Contact Rx-IT to help you navigate the new cybersecurity landscape.

We feel everyone should have access to the most robust cybersecurity available. We even offer packages for individuals. Check them out here.

Contact Rx-IT here: https://www.rx-it.com/contact/

Rx-IT on Facebook: https://www.facebook.com/RxITtech/

Rx-IT on Twitter: https://twitter.com/rxpc

Rx-IT on LinkedIn: https://www.linkedin.com/company/rx-it-technology-solutions

Rx-IT on GBP: https://www.google.com/maps/place/Rx-IT+-+IT+Service+and+IT+Support.+Managed+IT+Services/@38.7754595,-77.1814791,17z/data=!3m1!4b1!4m5!3m4!1s0x89b7ad591c8f83cf:0xfc365ffd839abf7b!8m2!3d38.7754553!4d-77.179285

Since 1999, Rx-IT has been a leading provider of IT support and consulting, focusing on small and medium sized businesses in Springfield VA, Arlington VA, Maryland, Boston, Fairfax County VA, Washington DC, NOVA and Suburban MD. We have helped hundreds of businesses increase productivity and profitability by making IT a streamlined part of operations. We equip our clients with customized technology solutions for greater operational value and to reduce risk.

Also, check out these pages.

https://www.rx-it.com/contact/

https://www.rx-it.com/referral-program-for-managed-it-services/

6564 Loisdale Ct, Suite 600, Springfield, VA 22150, 703-538-5533

233 Needham Street, Newton, MA 02464

6600 Chase Oaks Blvd, Ste 100, Plano, TX 75023

Used with permission from Article Aggregator