Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
The Internet

Browser Extensions Turn Nearly 1 Million Browsers Into Website-Scraping Bots (arstechnica.com) 14

Over 240 browser extensions with nearly a million total installs have been covertly turning users' browsers into web-scraping bots. "The extensions serve a wide range of purposes, including managing bookmarks and clipboards, boosting speaker volumes, and generating random numbers," reports Ars Technica. "The common thread among all of them: They incorporate MellowTel-js, an open source JavaScript library that allows developers to monetize their extensions." Ars Technica reports: Some of the data swept up in the collection free-for-all included surveillance videos hosted on Nest, tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive and Intuit.com, vehicle identification numbers of recently bought automobiles along with the names and addresses of the buyers, patient names and the doctors they saw, travel itineraries hosted on Priceline, Booking.com, and airline websites, Facebook Messenger attachments and Facebook photos, even when the photos were set to be private. The dragnet also collected proprietary information belonging to Tesla, Blue Origin, Amgen, Merck, Pfizer, Roche, and dozens of other companies.

Tuckner said in an email Wednesday that the most recent status of the affected extensions is:

- Of 45 known Chrome extensions, 12 are now inactive. Some of the extensions were removed for malware explicitly. Others have removed the library.
- Of 129 Edge extensions incorporating the library, eight are now inactive.
- Of 71 affected Firefox extensions, two are now inactive.

Some of the inactive extensions were removed for malware explicitly. Others have removed the library in more recent updates. A complete list of extensions found by Tuckner is here.

Browser Extensions Turn Nearly 1 Million Browsers Into Website-Scraping Bots

Comments Filter:
  • ...again. (Score:4, Funny)

    by Narcocide ( 102829 ) on Wednesday July 09, 2025 @09:37PM (#65508782) Homepage

    JavaScript was a mistake.

    • Compounded by dynamically including libraries downloaded from random website.
    • by dfghjk ( 711126 )

      it's not the language or that there is scripting, it's what the scripting has access to. Modern web browser architecture is a joke because developers have become incompetent.

      Can't wait for version 3!

    • Javascript alone can't do this, only browser extensions can. It's the extensions, not the language.

      • by znrt ( 2424692 )

        this was the issue here:

        "They incorporate MellowTel-js, an open source JavaScript library that allows developers to monetize their extensions."

        "developers" rushing to monetize their crap extension that they're not savy or caring enough to actually develop. wether they had bad intentions or not, these guys are simply not to be trusted anymore. something similar could be said about users installing that crap but then users are users.

        bottom line is that extensions are powerful tools but with their power comes at a risk. installing an extension is similar to running any random executable. no extension or library should ever be

        • I agree with you fully that extensions should not be trusted, unless you completely trust the company that made it. My point is that it's the extension that's evil, not the language. Without the extension, the language alone would not be able to inject the scraper into every single website you visit.

  • by zkiwi34 ( 974563 ) on Wednesday July 09, 2025 @10:14PM (#65508850)
    I guess that isn't much of a thing anymore.
    • Browser extensions have always been a wasteland of crappy useless widgets from noname companies.

      I once tried an extension that let me send and receive texts from my browser, and it was cool, until I realized what I was giving that company in the process. Since then, I've kept a bare minimum of extensions: uBlock Origin (Lite), Chrome Remote Desktop, Microsoft SSO, and Google Docs Offline. That's it. If I don't know the company that made an extension, I'm not allowing it into my browser.

      • I like to use ghostery in addition to uBlock Origin. I miss the non-lite version.
        • >"I like to use ghostery in addition to uBlock Origin. I miss the non-lite version."

          https://addons.mozilla.org/en-... [mozilla.org]
          https://addons.mozilla.org/en-... [mozilla.org]

          Perfectly non-"lite"

          As for malicious add-ons, there is the "Recommended" badge (that can be set as a filter as well) which helps a lot.

          https://support.mozilla.org/en... [mozilla.org]
          https://support.mozilla.org/en... [mozilla.org]

          Not surprisingly, both UBO and Ghostery are listed as "Recommended", along with 99 others (out of 58,708 addons). I will admit that of the 7 I am using at ho

          • by Anonymous Coward

            As for malicious add-ons, there is the "Recommended" badge (that can be set as a filter as well) which helps a lot.

            Seriously? You mean, if a developer is bribing mozilla to include his extension in its "recommended" list, that make you trust him more, not less?

  • Why would somebody clicks on a g-doc list if he or she dislikes the leak of personal information ?

    Curious about the list, I loosed. I clicked too fast without reading the link :-)

  • by Wolfling1 ( 1808594 ) on Thursday July 10, 2025 @05:42AM (#65509234) Journal
    Our websites take more Ddos style hits from anti-virus scans than anything else on some days.

"Lead us in a few words of silent prayer." -- Bill Peterson, former Houston Oiler football coach

Working...