Malicious extensions in Chrome Web store steal user credentials
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住主要信息。 文章讲的是Chrome商店里有两个名为“Phantom Shuttle”的扩展程序,伪装成代理服务插件,实际目的是劫持用户流量并窃取敏感数据。这两个扩展程序自2017年起活跃,主要针对中国用户,包括外贸工作者。它们通过订阅收费,并利用隐藏的代理凭证和恶意代码来窃取数据,包括密码、信用卡信息等。目前这些扩展仍在商店中存在。 接下来,我需要将这些关键点浓缩到100字以内。要确保涵盖伪装代理、劫持流量、窃取数据、目标用户、订阅模式以及当前状态。同时,语言要简洁明了。 可能会这样组织:Chrome商店的两个“Phantom Shuttle”扩展伪装成代理工具,实则劫持用户流量窃取敏感数据。针对中国用户,订阅收费模式,并利用隐藏凭证和恶意代码窃取信息。目前仍存在商店中。 检查字数是否在限制内,并确保没有使用开头模板。 </think> Chrome商店中的两个名为"Phantom Shuttle"的扩展伪装成代理工具,实则劫持用户流量并窃取敏感数据。这些扩展针对中国用户,采用订阅模式收费,并通过隐藏的代理凭证和恶意代码窃取用户信息。目前这些扩展仍在Chrome商店中活跃。 2025-12-23 13:45:46 Author: www.bleepingcomputer.com(查看原文) 阅读量:5 收藏

Malicious extensions in Chrome Web store steal user credentials

Two Chrome extensions in the Web Store named 'Phantom Shuttle' are posing as plugins for a proxy service to hijack user traffic and steal sensitive data.

Both extensions are still present in Chrome's official marketplace at the time of writing and have been active since at least 2017, according to a report from researchers at the Socket supply-chain security platform.

Phantom Shuttle’s target audience is users in China, including foreign trade workers who need to test connectivity from various locations in the country.

Wiz

Both extensions are published under the same developer name and are promoted as tools that can proxy traffic and test network speed. They are available for a subscription between $1.4 - $13.6.

The Phantom Shuttle extension on the Web Store
The Phantom Shuttle extension on the Web Store
Source: BleepingComputer

Covert data-theft functionality

Socket.dev researchers say that Phantom Shuttle routes all user web traffic through proxies controlled by the threat actor, accessible via hardcoded credentials. The code doing this is prepended to the legitimate jQuery library.

The malicious code hides the hardcoded proxy credentials using a custom character-index encoding scheme. Through a web traffic listener, the extensions can intercept HTTP authentication challenges on every website.

To automatically run user traffic through the attacker's proxies, the malicious extensions dynamically reconfigure Chrome’s proxy settings using an auto-configuration script.

In the default “smarty” mode, it routes more than 170 high-value domains through the proxy network, including developer platforms, cloud service consoles, social media sites, and adult content portals.

On the exclusion list are local networks and the command-and-control domain, to avoid disruption and detection.

While acting as a man-in-the-middle, the extension can capture data from any form (credentials, card details, passwords, personal info), steal session cookies from HTTP headers, and extract API tokens from requests.

BleepingComputer has contacted Google about the extensions still being present in the Web Store, but a comment wasn't immediately available.

Chrome users are advised to trust only extensions from reputable publishers, check multiple user reviews, and pay attention to the permissions requested upon installation.

tines

Break down IAM silos like Bitpanda, KnowBe4, and PathAI

Broken IAM isn't just an IT problem - the impact ripples across your whole business.

This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.


文章来源: https://www.bleepingcomputer.com/news/security/malicious-extensions-in-chrome-web-store-steal-user-credentials/
如有侵权请联系:admin#unsafe.sh