Skip to main content

A phony ad-blocking Chrome extension infiltrated Google's official Web Store

A phony ad-blocking Chrome extension infiltrated Google's official Web Store

Share this story

A phony AdBlock Plus extension was listed in Chrome’s official Web Store up until today, with more than 30,000 people having downloaded it. Anonymous cybersecurity personality @SwiftOnSecurity called attention to the fake extension and pointed out that imposters, like this fake AdBlock Plus, continue getting through the Google's vetting process and into the store's listings. That presents an especially tricky situation for users who might not carefully check each extension’s developer.

In this case, a developer going by “Adblock Plus” intentionally created an extension that looks just like the legitimate Adblock Plus, which is developed by adblockplus.org. More than 10 million people use the legitimate service. While the listing is no longer live, the knockoff developers still managed to convince 37,000 people to download it. We don't know if the extension was malicious or what data it might have compromised.

Google used to have a major problem with malicious Chrome extensions. The company admitted as much in 2015 when it officially blocked Windows and Mac users from downloading Chrome extensions not hosted on the Chrome Web Store. That move was meant to address concerns that users were downloading malicious software. The company said at the time that it saw a 75 percent drop in support requests for uninstalling unwanted extensions when it made this policy official for Windows users.

Still, we saw hackers return to this same naming trick in a widespread phishing attack earlier this year that spoofed Google itself. An attacker named a third-party web app "Google Docs," which tricked users into giving the app permission to access their address book and Gmail. In the aftermath of that attack, Google said it would work "to prevent this kind of spoofing from happening again."

At this point, it isn't clear how the company addressed the issue, and obviously, spoofing still presents a problem on the Chrome Web Store. We've reached out to Google for clarification on its security vetting process and whether it's looking into this malicious extension.

Google responded with this comment: "We pulled the phony Adblock Plus extension from the Chrome Web Store within minutes of being alerted. We're always working to improve how we detect malicious extensions, and will continue to update our security protections to help prevent these types of issues in the future."

Update 9:36 AM ET, 10/12: Updated to include comment from Google.

Today’s Storystream

Feed refreshed 10 minutes ago Better on the inside

R
Quote
Richard Lawler10 minutes ago
Adnan is out.

Yesterday, a Baltimore City Circuit judge overturned the murder conviction of Adnan Syed, setting him free — for the moment — after serving 23 years in a case documented by the podcast Serial. This morning, host Sarah Koenig released Serial’s first new episode in seven years.

It’s Baltimore, 2022. Adnan Syed has spent the last 23 years incarcerated, serving a life sentence for the murder of Hae Min Lee, a crime he says he didn’t commit. He has exhausted every legal avenue for relief, including a petition to the United States Supreme Court. But then, a prosecutor in the Baltimore State’s Attorney’s office stumbled upon two handwritten notes in Adnan’s case file, and that changed everything.


J
External Link
James VincentAn hour ago
For every living human there are 2.5 million ants, say scientists, unprompted.

I honestly don’t know what to do with this information, which comes via The Washington Post. This is just one guy’s opinion, but it seems like an awful lot of ants. Like God accidentally maxed out the ant-slider or spilled a bag of “Oops! All ants!” into the biosphere during Creation. What I need is a lie down and to not think about the millions — sorry, 20 quadrillion — of ants out there.


T
External Link
Thomas Ricker9:01 AM UTC
Pixel Watch to start at $349.99?

9to5Google reports that the Bluetooth/Wi-Fi model of the Pixel Watch will start at $349.99, after having previously reported the cellular model will cost $399.99. That puts them above Samsung’s $279.99 Galaxy Watch 5 and closer to what Apple charges (starting at $399 for the Series 8). We’ll know for sure come October 6th.


Welcome to the new Verge

Revolutionizing the media with blog posts

Nilay PatelSep 13
N
External Link
Nilay Patel3:25 AM UTC
“Obviously Peacock sucks.”

Kim Masters has a good piece on Warner Brothers Discovery looking for a new DC studio chief, with rampant speculation that the endgame is Comcast buying the whole thing in 2024 to beef up Peacock.

Many top industry execs are so convinced a deal will happen that some are pre-mourning an event that may never happen. “People feel like it’s Comcast for sure,” says the head of one company. “It’s going to be so depressing to lose another major studio [after Disney bought Fox]. And Warners was the Tiffany studio.”


N
The Verge
Nathan Edwards2:30 AM UTC
How’s that eSIM-only iPhone working out for you?

In my article about Apple dropping the physical SIM on the iPhone 14, I said it was “probably fine” for people on major US carriers. I also mentioned that my iPhone 11 had a physical Verizon SIM and an eSIM from a carrier in the Netherlands. This weekend I upgraded to an iPhone 14 Pro. The Verizon SIM transferred without a hitch. The other one? Not so much. Guess it’s time to admit to myself that I’m never moving back to Amsterdam.


M
External Link
Mitchell Clark1:50 AM UTC
More testimony on how working at Tesla is a nightmare for women.

Rolling Stone interviewed five women involved in the several sexual harassment lawsuits against the automaker.

Hearing them describe how they were treated, and how Tesla failed to defend them (and sometimes actively punished them) is difficult.


N
External Link
Nilay Patel1:36 AM UTC
Amazon says streaming Thursday Night Football was a huge success.

The official Nielsen numbers aren’t in, but a memo from Amazon’s Jay Marine says the game was “the most watched night of primetime in the U.S. in the history of Prime Video” and he expects the company exceeded the 12.5 million viewers it promised advertisers.

Amazon can’t go five minutes without pushing an unverifiable and unquantifiable statistic, so Marine also claimed the game was “the biggest three hours for U.S. Prime sign ups ever in the history of Amazon — including Prime Day, Cyber Monday and Black Friday.” Truly the emptiest of data points from the people who run Next Gen Stats Powered By AWS.


M
External Link
Mitchell Clark1:20 AM UTC
It sounds like the DOJ isn’t happy with the Apple v. Epic ruling

According to TechCrunch, the Department of Justice will be allowed to argue its concerns about the original ruling during the appeal trial.

The DOJ is worried the decision as it stands could make future antitrust cases more difficult — which is especially important considering reports that it’s working on its own antitrust action against Apple.


A
External Link
Adi RobertsonSep 19
I don’t think this AI-generated game actually counts as AI-generated.

This Girl Does Not Exist promises “everything you will see in this game” is created by an AI. Except... based on everything I’ve read, that includes none of the game mechanics or interface design! It’s an interesting experiment in artificially generated images and audio, but AI-generated gameplay is a uniquely weird and difficult problem. That said, I’m fascinated by the growing move toward an aesthetics of AI — and this project sits square in that zone.


D
External Link
David PierceSep 19
This is an awesome guide to iOS 16 lock screen widgets.

I continue to think they’re the best thing about the new iOS, and the MacStories folks rounded up a huge number of widgets you can try now. They range from pointless and delightful to totally instantly essential — Link Hub, which just opens any link you want, is particularly great.


A
Alex CranzSep 19
Music labels are incorporating old songs into new songs to trigger your nostalgia.

The Vergecast is doing a special miniseries for the next three Mondays on the future of music. This week I spoke with music reporter and podcaster Charlie Harding about how the future of music could sound very familiar.


A
External Link
Adi RobertsonSep 19
Rick and Morty and the high-wire act of writing antiheroes.

Countless people have discussed the travails of Rick and Morty fandom. But Corbin Smith goes beyond the simple claims that obnoxious fans are just watching the show wrong, delving into the inherent difficulty of writing a character with terrible qualities who’s still undeniably cool to watch. A bonus: he lays out the precise take on Rorschach from Watchmen that I’ve always wanted to read.


E
External Link
My “I’m not on the run” t-shirt is raising questions answered by my t-shirt.

South Korean authorities have requested that Interpol tell international authorities to arrest Do Kwon, the co-founder of the company behind the Terra/Luna cryptocurrency debacle, The Financial Times reports. Kwon tweeted this weekend that he is not on the run, actually, and authorities are just mad that he tweeted that their size is not size. Posters gonna post, I guess.


E
External Link
The 2010s were about lifestyle brands. What’s next?

Loved this meaty essay about trends in consumerism, what we mean by “culture,” and how DTC brands led to a new understanding of community and identity. “In the 2010s, supply chain innovation opened up lifestyle brands. In the 2020s, financial mechanism innovation is opening up the space for incentivized ideologies, networked publics, and co-owned faiths,” writes Toby Shorin. “The authenticity-driven culture of ironic detachment, so present in the early 2000s, has given way to a moment where people are genuinely open to being influenced, open to sincerely participating, even if it’s cringe.”


Life After Lifestyle

[subpixel.space]

J
The Verge
“I still stand by that tweet.”

–Figma CEO Dylan Field, in the unenviable position of having to reflect on an old tweet.

Field tweeted last year that Figma’s goal “is to be Figma not Adobe.” Fast forward to today and... Figma is going to be part of Adobe! My colleague Jay Peters spoke with the two companies’ leaders about what the merger means for designers everywhere.


R
Richard LawlerSep 19
Steam Deck display docks, and Deck deliveries.

Steam Deck prototypes aren’t the only thing to see at the Tokyo Game Show, as one Redditor noticed (via PC Gamer) that the still-unreleased official dock is holding up display units.

That’s also relevant because Steam Decks are being delivered more rapidly than expected. Valve just announced it’s cleared the reservations in the Q3 bucket a couple of weeks ahead of schedule and is starting in on reservations slated for Q4.