logo

Hidden Exfiltration Capability Discovered in a Trusted, 900,000-User Chrome Web store Extension 

ID: 96628f60-2301-5731-9dc9-05d52373d868

STIX ID: report--96628f60-2301-5731-9dc9-05d52373d868

Feed Name: Threat Research – Stripe OLT

Threat Score
78/100

Date Published: 2026-07-13

Date Updated: 2026-07-16

Author: Hannah Evenden-Morley

...
...

A signed Chrome Web Store release of the popular ModHeader extension (v7.0.18) was found to include a dormant but complete browsing-history collection and exfiltration pipeline that fingerprints devices, encrypts visited domains with a hardcoded AES-GCM key, stages data in IndexedDB, and is designed to POST encrypted telemetry to api.stanfordstudies.com while beaconing install/update/uninstall events to extensions-hub.com; Google removed the extension from the store after responsible disclosure, but installed copies remain a significant enterprise supply-chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.