TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Help with suspected malware extension with 10M users

14 点作者 matusfaro将近 2 年前
In last two days, my friend had her CC stolen and Instagram taken over which she accessed from her Mac. Although a rootkit is possible, her browser had three extensions: ublock origin, Google Drive, and &quot;WebChatGPT&quot; [1].<p>Looking into WebChatGPT:<p>- It has full access to all sites<p>- Extension was recently sold by owner [2]<p>- Latest release [3] doesn&#x27;t match any new commits in the open-source repo [4].<p>- The last change in the repo removes sponsor link for buy me a coffee<p>- Someone opened an issue on the repo calling out spyware [5]<p>What is the best course of action here? Where can we report this? I am going to try to download the extension and follow where the data is sent.<p>* 1 https:&#x2F;&#x2F;tools.zmo.ai&#x2F;webchatgpt<p>* 2 https:&#x2F;&#x2F;www.buymeacoffee.com&#x2F;anzorq<p>* 3 https:&#x2F;&#x2F;addons.mozilla.org&#x2F;en-US&#x2F;firefox&#x2F;addon&#x2F;web-chatgpt&#x2F;versions&#x2F;<p>* 4 https:&#x2F;&#x2F;github.com&#x2F;interstellard&#x2F;chatgpt-advanced<p>* 5 https:&#x2F;&#x2F;github.com&#x2F;interstellard&#x2F;chatgpt-advanced&#x2F;issues&#x2F;203

5 条评论

dinp将近 2 年前
You can add reviews under the chrome and firefox extensions to warn other users and then report both extensions (assuming you are confident about your findings).<p>More of a meta comment: this is pretty much why I don&#x27;t install any extensions in my browser except an ad blocker.<p>You can use this as an opportunity to teach your friend about security so it doesn&#x27;t happen again.
评论 #36734037 未加载
p-e-w将近 2 年前
&gt; What is the best course of action here? Where can we report this?<p>There is a huge button &quot;Report this add-on for abuse&quot; on every single extension page on addons.mozilla.org.
matusfaro将近 2 年前
Firefox recently added capability to remotely disable extensions [1]. Although I was also concerned with the feature when I saw it, I can see how that would be useful in exactly this scenario.<p>* - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36602193">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36602193</a>
brucethemoose2将近 2 年前
There really need to be some extension store changes. The stores as they exist are not sustainable. Just spitballing:<p>- No binary or closed source releases, Google&#x2F;Mozilla compile from a public source.<p>- More zealous restrictions (which admitedly Google is already heading towards)<p>- Big fat warnings when accessing cookies or secure fields like passwords or CC. If this makes password managers look scary, good, they <i>should</i> look scary.
评论 #36734002 未加载
KomoD将近 2 年前
I looked at it a little bit and didn&#x27;t find anything super obvious about collecting info but it does look like it injects ads for their own services into google search results