Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates
ID: f87ceb07-7327-5dc5-b4c5-31a9d5e5f86b
STIX ID: report--f87ceb07-7327-5dc5-b4c5-31a9d5e5f86b
Feed Name: Socket Blog
Malicious Chrome and Firefox extensions branded as "VPN Go" and "Free VPN by VPN GO" introduced clipboard-stealing code in staged updates that monitors navigator.clipboard.readText, chunks copied content, tags it with session IDs, and exfiltrates data via HTTP GET requests to hardcoded endpoints (/html/continue.php) on infrastructure including 178.236.252.133, 178.236.252.161, and 77.91.123.187. The report provides versioned SHA256 hashes, extension IDs, manifest and script excerpts, observed bearer tokens and query parameters (uid, part, total, data), documents proxy functionality used as cover, notes user counts and reviews, and recommends removal, hunting for outbound HTTP to the listed endpoints, and tightening extension installation policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
