Bonum Certa Men Certa

Malware-Addled Chrome Web Store to “Warn About Malware”



Reprinted with permission from Ryan Farmer. Also available in Gemini.

Malware-Addled Chrome Web Store to “Warn About Malware”.



Chrome’s extension store crawls with malware.



If you install any significant number of extensions from the store, then you will eventually have malware.



One of the more common ways to get malware from Chrome’s extension store is when a “good extension goes bad”. Extensions with many users are worth a lot of money to hijackers. Quite often they’ll pay the developer off, push out an update to the users, quietly, with the malicious payload, and then sit pretty on a fat stack of dirty money before Google gives them the boot.



Since it’s not difficult to push malicious extensions, hijack existing ones, and make new developer accounts (for five whole dollars), the malware problem with Chrome extensions probably won’t subside any time soon.



But Google claims that they’re going to run “malware scans” or something, which have never cleaned up Windows, so good luck with that I guess. This “we’ll just keep an eye on it for you with a scanner while you do loads of stupid things” “Windows-style” “security” has literally never worked, at least not reliably.



I don’t typically install extensions, and when I do they’re usually more established and open source, into my Gecko browsers (SeaMonkey, LibreWolf, Firefox ESR), and when it’s open source you can have eyes on the extension.



Google’s Chrome extension store STILL won’t even tell you which license you are agreeing to, so you are giving the author a blank check each time you install one.



Meanwhile, Google is putting much effort into crippling the extensions platform so that ad blockers and NoScript don’t work well or can’t even be made to work at all, or their own ads get a pass.



Chrome is a malicious program.



It’s basically a Trojan horse (something that appears desirable, but in fact comes packed with things you wouldn’t accept if you knew it was being done).



It’s a disaster for your privacy and security. If you’re smart, you’ll never put it on your computer.

Recent Techrights' Posts

Parties and Milestones Again
we've begun putting up about 40 balloons
Microsoft is Disloyal Towards Its Most Loyal Employees
Against its most faithful enablers
 
The Cocaine Patent Office - Part II: The Person Who Planted Paid-for Fake News for the European Patent Office (EPO) is a Cocaine User, Friend of António Campinos, Now on Record as Having Been Arrested
Background: High-level manager at the European Patent Office caught in public with cocaine, arrested
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, October 27, 2025
IRC logs for Monday, October 27, 2025
Google News Drowning in Slop (and Slopfarms That Hijack About Half the Results)
Google News seems to be drowning in this stuff
Gemini Links 28/10/2025: "How to Maximize Your Positive Impact" and ASCII Art and Artist Attribution
Links for the day
PETA and Activism
Being staff or volunteer in PETA isn't easy
Big Blue, Huge Debt
debt will soar again
Links 27/10/2025: Mass Surveillance Sold as "AI", People Reluctant to Lose Physical Media
Links for the day
Techrights' 19th Anniversary: Bronze
Time to go back to preparing for this anniversary
Our Latest European Patent Office (EPO) Series Will Last Several Weeks, Will Ask the EPO Management and the European Union (EU) Very Difficult Questions
If nobody loses a job (or jobs) over this, then the EU basically became no better than Colombia or Nicaragua
Slopwatch: LinuxSecurity, UbuntuPIT, Brian Fagioli, and Google News
We focus on stories that are fake or LLM slop that disguises itself as "news" about Linux
Links 27/10/2025: Wikipedia Vandalism, Bruce Perens Opens up on Childhood
Links for the day
This Site Could Not be Done by LLMs Even If It Wanted to (Because It's Not a Parrot of What Other Sites Say)
LLMs have no knowledge or deep understanding
19 Years, No Censorship
No factual information is ever going to be removed, more so if it is in the public interest
We Are Not a Conventional Site, That's Why They Hate (or Love) Us
Throughout the week this week we'll be focusing on the EPO
Following the Line of Cocaine All the Way to the Top
Even a million denials and spin-doctoring won't distract from the core issue
The Cocaine Patent Office - Part I: António Campinos Brought Corruption and Nepotism to the EPO, Then Came the Cocaine
High-level manager at the European Patent Office (EPO) caught in public with cocaine, the Office has some answering to do
Purchasing/Possessing Computers Isn't the Same as Controlling Computers
Let's strive to put computers back under the control of their users, no matter who purchased these (usually the users)
Gemini Links 27/10/2025: Alhena 5.4.3 and Fixing Bash
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, October 26, 2025
IRC logs for Sunday, October 26, 2025
Thankfully We've Made Copies of More Interesting Data From statCounter
If statCounter (the Web site or the 'webapp') vanished overnight, we'd still have something left of it
More Silent Layoffs at IBM/Red Hat
when the media counts such layoffs or presents tallies the numbers are very incomplete
Links 26/10/2025: Microsoft Spies on Gamers, Open Transport Community Conference
Links for the day
Links 26/10/2025: LLM Slop / Plagiarism Programs Continue to Disappoint, CISA Layoffs Threaten Systems
Links for the day
Gemini Links 26/10/2025: Gemsync and Joining the Small Web
Links for the day
India.com a Click-baiting, SEO-Spamming, Slopfarming Heap
They do this almost every day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, October 25, 2025
IRC logs for Saturday, October 25, 2025
Without XBox Consoles, XBox is No More, It's Just a Brand (More Rumours of Microsoft Ending XBox, Then Laying Off Lots of Staff)
All signs indicate that Microsoft wants to "exit" the XBox business (not brand), but it does not want to publicly admit this as it would alarm staff and shareholders