New ask Hacker News story: Ask HN: Help with suspected malware extension with 10M users
Ask HN: Help with suspected malware extension with 10M users
12 by matusfaro | 7 comments on Hacker News.
In last two days, my friend had her CC stolen and Instagram taken over which she accessed from her Mac. Although a rootkit is possible, her browser had three extensions: ublock origin, Google Drive, and "WebChatGPT" [1]. Looking into WebChatGPT: - It has full access to all sites - Extension was recently sold by owner [2] - Latest release [3] doesn't match any new commits in the open-source repo [4]. - The last change in the repo removes sponsor link for buy me a coffee - Someone opened an issue on the repo calling out spyware [5] What is the best course of action here? Where can we report this? I am going to try to download the extension and follow where the data is sent. * 1 https://ift.tt/V8pUldH * 2 https://ift.tt/EuJnv9Y * 3 https://ift.tt/vctodF0 * 4 https://ift.tt/dpC8vFQ * 5 https://ift.tt/ySAo2zk
12 by matusfaro | 7 comments on Hacker News.
In last two days, my friend had her CC stolen and Instagram taken over which she accessed from her Mac. Although a rootkit is possible, her browser had three extensions: ublock origin, Google Drive, and "WebChatGPT" [1]. Looking into WebChatGPT: - It has full access to all sites - Extension was recently sold by owner [2] - Latest release [3] doesn't match any new commits in the open-source repo [4]. - The last change in the repo removes sponsor link for buy me a coffee - Someone opened an issue on the repo calling out spyware [5] What is the best course of action here? Where can we report this? I am going to try to download the extension and follow where the data is sent. * 1 https://ift.tt/V8pUldH * 2 https://ift.tt/EuJnv9Y * 3 https://ift.tt/vctodF0 * 4 https://ift.tt/dpC8vFQ * 5 https://ift.tt/ySAo2zk
Comments
Post a Comment