heathdbrown / research

Things to look at it or that interest me.
0 stars 0 forks source link

Possible malicious extension review? #59

Closed nicoleahmed closed 7 months ago

nicoleahmed commented 10 months ago

Hi Heath Are you the Heath Brown that wrote the review here

If you are I wanted to say thank you first. And get your opinion on a couple of things.

If you aren't - sorry! I'll delete this :)

This is my reply on your review: Heath I'm so glad there are people taking the issue of malicious extensions seriously. Thanks for writing your guide up. I've found that virustotal doesn't really detect malicious extensions - have you found it does? And when decompiling the code how have you managed the issue of obfuscation? Or where the extension begins malicious activity a set number of weeks after installing? Would love to get your thoughts...

I've been working on two things (which is based off other peoples work too): https://github.com/nicoleahmed/malicious-extensions-list - compiling a list of malicious extensions so people can check they aren't affected https://github.com/nicoleahmed/ChromeWebStoreSorter a bookmarklet to sort chrome store results - most ratings at top

heathdbrown commented 7 months ago

Not me