puemos / hls-downloader

Web Extension for sniffing and downloading HTTP Live streams (HLS)
https://puemos.gitbook.io/hls-downloader/
MIT License
1.88k stars 232 forks source link

duplicate extension listed on Chrome Web Store until today, taken down due to "malware" #306

Open vt-idiot opened 10 months ago

vt-idiot commented 10 months ago

There was a duplicate extension listed on the Chrome Web Store, or rather, I just realized it was a duplicate when I came here, saw the message about it being delisted from CWS because of a copyright claim...and noticing it had been in README.MD for over a year...I had no idea it was a duplicate, but I had it installed. Today I got a notification telling me it was disabled for containing malware. Of course, Google doesn't say anything else, and I have no idea what the extension was actually doing (minified JS?) or if any of my data is at risk.

I am aware there is no association between this extension and the copycat, but I am hoping that someone here who is familiar with the original extension can look at it and let me know if I should be nuking everything...

https://chrome-stats.com/d/fopnhepeflgcnppklfnejokkkeomdgik

Attached is the source code to the final version, 3.2.1.3, before it was delisted. Do not install this fopnhepeflgcnppklfnejokkkeomdgik.zip

puemos commented 10 months ago

Definitely a copy

FabriceSalvaire commented 9 months ago

@vt-idiot replace ; by ;\n to split lines and then look at code. I found a lot of Facebook urls. The second extension of this developer was also targeting Facebook... There are also Twitter and LinkedIn urls.