• START
  • SCRAPING
    • SCRAPING DEFINED
    • SCRAPER BOTS
    • SCRAPING THREATS
    • SECTORS AT RISK
  • SERVICES
  • CLIENTS
  • ABOUT
  • RESOURCES
    • SCRAPING NEWS
    • CASE STUDIES
    • THE SCRAPING THREAT REPORT 2015
  • CONTACT

Blog Post

07
APR
2015

ScrapeSentry Finds Security Breach in Google Chrome Extension

Posted By : admin
Comments : Off

Researchers at leading anti-scraping and IT security specialists ScrapeSentry have uncovered a sinister side effect to a free app which over a million Google Chrome users have downloaded, and which potentially leaks all of their personal information back to a single IP address in the USA.

Webpage Screenshot which is available in the Google Chrome Extension web store has now been downloaded by over 1.2 million users.   The extension allows users to take a screen capture and store it.  But hidden in it is a more menacing data theft capability.

Explaining how they discovered the hidden functionality, Martin Zetterlund, Founding Partner at ScrapeSentry said, “We are in the business of detecting and blocking scrapers and bots that break terms and conditions of use of our customers’ websites. We recently identified an unusual pattern of traffic to one of our client’s sites which alerted our investigators that something was very wrong.”

On further analysis, the team discovered that the Chrome extension contained malicious code that allowed for copies of all browser all your browsing data to a server in the USA. This means that all the sensitive data visible in your page title, such as e-mail if you’re using a web e-mail service, could be sent unknowingly to an IP address hosted in the USA.

Cristian Mariolini, Security Analyst, who headed up the team that found the rogue extension  concluded, “The repercussions of this could be quite major for the individuals who have downloaded the extension.  What happens to the personal data and the motives for  wanting it sent it to the US server is anyone’s guess, but ScrapeSentry would take an educated guess it’s not going to be good news.  And of course, if it’s not stopped, the plugin may, at any given time, be updated with new malicious functionality as well.  We would hope Google will look into this security breach with some urgency.” 

* * *

For details about how we found the leaking extension:
https://www.scrapesentry.com/the-leaking-chrome-extension/

* * *

Notes to Editors:

About ScrapeSentry

ScrapeSentry was founded in 2006, and was the world’s first anti-scraping solution to be developed to protect sites from the loss of Intellectual Property and from data theft.  As pioneers in the field, ScrapeSentry has worked with many global businesses, such as easyJet, Ladbrokes, and Autotrader.com to protect them from scraping and all the costs, losses of data, customers and IP as well as the potential losses in the reputational damage, that scraping involves. ScrapeSentry has offices in Stockholm, Sweden London, UK  and Boston USA.

About Scraping:

Scraping (also known as web scraping, screen scraping or data scraping) is where large amounts of data from a web site is copied manually or with a script or program. Scrapers might be copying data to populate their own site, or to pretend to be you to customers, or to ensure they price match or better.  Whatever their motive and final use for your data, web scrapers are likely to be competing for your customers.  Scraping can also have the unintended (or sometimes the intended) consequence of also slowing access to the scraped site and to customers being unable to complete transactions, so that they abandon the site and go elsewhere

Social Share

Need to talk to an expert?

We have helped several companies in various sectors since 2006. Are you afraid that your business is at risk? Then you should talk to one of our anti scraping experts. We operate with integrity and respect your confidentiality.
Contact us today!

Stop scraping and bad bots with ScrapeSentry

ScrapeSentry is a complete combination of technology, behavioral analysis, expertise and most importantly 24/7 human moderation. Find out how ScrapeSentry can secure your business!
Read more!

Recent Articles

Distil Networks Acquires Sentor ScrapeSentry to Add 24/7 Security Operations Center and Expert Team of Analysts

January 13, 2020

When Reservation Bots Steals Your Favorite Table

November 10, 2020

Data Scraping – Terms & Conditions

September 07, 2020

How Python Is Used to Scrape Websites

September 02, 2020

Price Scraping a Growing Threat to Ecommerce Sites

August 20, 2020

ScrapeSentry - The Anti Scraping Service

We offer guaranteed detection and scraping prevention in near real-time. A combination of technology, behavioral analysis, expertise and most importantly 24/7 human moderation.
More about ScrapeSentry!

The Scraping Threat Report 2015

The Scraping Threat Report 2014 is a report based on data from the world's largest database for scraping related activity. The report shows an huge increase in scraping related activity.
Download the report!

Recent Articles in our Newsroom

Distil Networks Acquires Sentor ScrapeSentry to Add 24/7 Security Operations Center and Expert Team of Analysts

January 13, 2020

When Reservation Bots Steals Your Favorite Table

November 10, 2020

Data Scraping – Terms & Conditions

September 07, 2020

How Python Is Used to Scrape Websites

September 02, 2020

Price Scraping a Growing Threat to Ecommerce Sites

August 20, 2020

Contact Distil Networks:

[email protected]
US: (866) 598-6787
UK: +44 203 3184751
EU: +46 8 545 333 50

East Coast Headquarters:

4501 North Fairfax Drive
Suite 120
Arlington, VA 22203

West Coast Headquarters:

49 Stevenson St.
Suite 200
San Francisco, CA 94105

European Headquarters:

Björn Trädgårdsgränd 1
116 21 Stockholm
Sweden
Copyright © 2016 Distil Networks. All rights reserved.