Malicious Chrome and Firefox VPN Extensions Add Clipboard Stealers Through Updates

· Original article ↗

Summary

Socket researchers found Chrome and Firefox VPN Go extensions added clipboard-stealing code in later versions, sending copied data to hardcoded servers. The extensions were reported to Google and Mozilla for review.

Key points

  • The Chrome extension added confirmed clipboard theft in versions 1.1–1.3; the Firefox extension added it in versions 1.3.3–1.3.4.
  • The extensions polled the clipboard, split new copied text into chunks, and exfiltrated it over HTTP to hardcoded servers.
  • Copied passwords, MFA codes, API keys, tokens, and other secrets may have been exposed.
  • The Chrome and Firefox versions shared exfiltration infrastructure; observed IPs were 178[.]236[.]252[.]133, 178[.]236[.]252[.]161, and 77[.]91[.]123[.]187.
  • Both extensions also provided proxy functionality, which gave them a plausible VPN purpose while clipboard monitoring ran in the background.
  • Socket reported the extensions to Google and Mozilla. Users are advised to remove them and treat secrets copied while they were installed as exposed.

Article Details

Attack Vectors
  • Browser extensions marketed as free VPNs introduced clipboard theft through staged updates: Chrome versions 1.1–1.3 and Firefox versions 1.3.3–1.3.4 were confirmed malicious.
  • The Chrome extension added clipboardRead permission and a content script running on all websites at document_start. It polled the clipboard every 500 milliseconds and forwarded copied text to its background service worker.
  • The Firefox extension read clipboard contents directly from its background script every 1.5 seconds.
  • Both implementations skipped duplicate clipboard values, split newly copied text into approximately 1,000-character chunks, assigned session identifiers, and transmitted chunks through HTTP GET requests with uid, part, total, and data query parameters.
  • Functional proxy configuration and misleading no-data-collection claims provided cover for clipboard theft. Static analysis showed that the extensions could route browser traffic through threat actor-supplied infrastructure; researchers did not dynamically validate the proxy service.
Defensive Notes
  • Remove the identified malicious VPN extensions from Chrome and Firefox.
  • Treat secrets copied while the extensions were active as exposed, including passwords, API keys, access tokens, cloud credentials, MFA recovery codes, and cryptocurrency recovery material.
  • Inventory browser extensions across managed endpoints and prioritize review of extensions requesting clipboard access, proxy control, tab access, webRequest-related permissions, or access to all websites.
  • Hunt for outbound HTTP requests to the reported clipboard-exfiltration endpoints, particularly requests containing uid, part, total, and data query parameters.
  • Restrict installation to approved extension IDs, enforce browser management policies, and review permission changes before allowing updates.
  • Investigate newly added clipboardRead permissions or content scripts running on all websites when those capabilities are unnecessary for the extension's stated purpose.
  • Socket reported both extensions to Google and Mozilla for review and removal; the article does not confirm removal.

Indicators of compromise

TypeIndicatorContext
EMAILinfo@vpngogmail[.]comContact email in the malicious extensions' misleading privacy policy and explicitly included in the article's indicators.
EMAILzegivati83@gmail[.]comDeveloper registration email listed for the malicious Chrome extension and explicitly included in the article's indicators.
IPV4178[.]236[.]252[.]133Threat actor-controlled clipboard-exfiltration and proxy-location infrastructure used by Chrome versions 1.1 and 1.2.
IPV4178[.]236[.]252[.]161Threat actor-controlled clipboard-exfiltration and proxy-location infrastructure used by Firefox 1.3.3.
IPV477[.]91[.]123[.]187Shared threat actor-controlled clipboard-exfiltration and proxy-location infrastructure used by Chrome 1.3 and Firefox 1.3.4.
SHA2562fe9c41901045013ba28ccb9af5870f9aef4f1ffd1e717cd5e0189ffdbe7fca2SHA256 of the confirmed malicious Firefox XPI version 1.3.4.
SHA25643dc5b1d4c73d5ed9f4f7f561830079896eeb533a7c21bc577e4e267d5a3aa56SHA256 of the confirmed malicious Chrome CRX version 1.1.
SHA25672fc06a8b03720f4a64744eecd5b3f658ad880bdb327c0c465c7bdc66b14a8d2SHA256 of the confirmed malicious Chrome CRX version 1.3.
SHA256b3b63970833b3379ecec2d3ef8fea328fef8dd1c1574b1bcdfebad5bdce9280cSHA256 of the confirmed malicious Chrome CRX version 1.2.
SHA256fbbdf4bc490ad7b28953630c1707aa68b89d319b9b735f3d8563320b81b21a97SHA256 of the confirmed malicious Firefox XPI version 1.3.3.
URLhxxp[:]//178[.]236[.]252[.]133/html/continue[.]phpClipboard-exfiltration URL shown in the Chrome background-script code for versions 1.1 and 1.2.
URLhxxp[:]//178[.]236[.]252[.]133/locationsThreat actor-controlled proxy-location retrieval endpoint used by Chrome versions 1.1 and 1.2.
URLhxxp[:]//178[.]236[.]252[.]161/html/continue[.]phpClipboard-exfiltration endpoint used by Firefox 1.3.3.
URLhxxp[:]//178[.]236[.]252[.]161/locationsThreat actor-controlled proxy-location retrieval endpoint used by Firefox 1.3.3.
URLhxxp[:]//77[.]91[.]123[.]187/html/continue[.]phpClipboard-exfiltration URL shown in the Chrome 1.3 background-script code.
URLhxxp[:]//77[.]91[.]123[.]187/locationsThreat actor-controlled proxy-location retrieval endpoint used by Chrome 1.3 and Firefox 1.3.4.
URLhxxps[:]//telegra[.]ph/Privacy-Policy-12-11-127Specific privacy-policy resource used by the malicious extensions to make misleading claims that no personal or user data was collected.

MITRE ATT&CK

Malware

Vendors

Products

Tools

Related Articles