TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Help with suspected malware extension with 10M users

14 pointsby matusfaroalmost 2 years ago
In last two days, my friend had her CC stolen and Instagram taken over which she accessed from her Mac. Although a rootkit is possible, her browser had three extensions: ublock origin, Google Drive, and &quot;WebChatGPT&quot; [1].<p>Looking into WebChatGPT:<p>- It has full access to all sites<p>- Extension was recently sold by owner [2]<p>- Latest release [3] doesn&#x27;t match any new commits in the open-source repo [4].<p>- The last change in the repo removes sponsor link for buy me a coffee<p>- Someone opened an issue on the repo calling out spyware [5]<p>What is the best course of action here? Where can we report this? I am going to try to download the extension and follow where the data is sent.<p>* 1 https:&#x2F;&#x2F;tools.zmo.ai&#x2F;webchatgpt<p>* 2 https:&#x2F;&#x2F;www.buymeacoffee.com&#x2F;anzorq<p>* 3 https:&#x2F;&#x2F;addons.mozilla.org&#x2F;en-US&#x2F;firefox&#x2F;addon&#x2F;web-chatgpt&#x2F;versions&#x2F;<p>* 4 https:&#x2F;&#x2F;github.com&#x2F;interstellard&#x2F;chatgpt-advanced<p>* 5 https:&#x2F;&#x2F;github.com&#x2F;interstellard&#x2F;chatgpt-advanced&#x2F;issues&#x2F;203

5 comments

dinpalmost 2 years ago
You can add reviews under the chrome and firefox extensions to warn other users and then report both extensions (assuming you are confident about your findings).<p>More of a meta comment: this is pretty much why I don&#x27;t install any extensions in my browser except an ad blocker.<p>You can use this as an opportunity to teach your friend about security so it doesn&#x27;t happen again.
评论 #36734037 未加载
p-e-walmost 2 years ago
&gt; What is the best course of action here? Where can we report this?<p>There is a huge button &quot;Report this add-on for abuse&quot; on every single extension page on addons.mozilla.org.
matusfaroalmost 2 years ago
Firefox recently added capability to remotely disable extensions [1]. Although I was also concerned with the feature when I saw it, I can see how that would be useful in exactly this scenario.<p>* - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36602193">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36602193</a>
brucethemoose2almost 2 years ago
There really need to be some extension store changes. The stores as they exist are not sustainable. Just spitballing:<p>- No binary or closed source releases, Google&#x2F;Mozilla compile from a public source.<p>- More zealous restrictions (which admitedly Google is already heading towards)<p>- Big fat warnings when accessing cookies or secure fields like passwords or CC. If this makes password managers look scary, good, they <i>should</i> look scary.
评论 #36734002 未加载
KomoDalmost 2 years ago
I looked at it a little bit and didn&#x27;t find anything super obvious about collecting info but it does look like it injects ads for their own services into google search results