Dormant remote-controlled JavaScript injection path in Adblock for YouTube Chrome extension
Technical Analysis
Summary
Hide ▲
Show ▼
A Chrome extension with 10 million+ installs was found to carry a dormant script-injection path, raising the risk of arbitrary JavaScript execution across visited websites. A single server-side change could activate the behavior without an extension update or store review. The extension’s youtube.com check can be bypassed by embedding the string anywhere in a URL, allowing the code path to reach non-YouTube pages. That could expose pages, credentials, and authenticated sessions even though no malicious payload distribution was observed.
Related Happenings
Silent Swap browser-extension clipboard clipper
Malware Activity
H score36
First: 30.06.2026 18:40
Last: 30.06.2026 18:40
Sources 1
About this happening:
The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
Silent Swap browser-extension clipboard clipper
Malware ActivityAbout this happening: The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
108 Malicious Google Chrome extensions sharing a C2 backend
Malware Activity
H score11
First: 14.04.2026 11:35
Last: 14.04.2026 11:35
Sources 1
About this happening:
108 malicious Google Chrome extensions were found to use the same C2 infrastructure to steal credentials, sessions, and browsing data while injecting ads and arbitrary Jav...
108 Malicious Google Chrome extensions sharing a C2 backend
Malware ActivityAbout this happening: 108 malicious Google Chrome extensions were found to use the same C2 infrastructure to steal credentials, sessions, and browsing data while injecting ads and arbitrary Jav...
ShieldGuard browser-extension data-harvesting malware
Malware Activity
H score29
First: 18.03.2026 16:15
Last: 18.03.2026 16:15
Sources 1
About this happening:
A malicious ShieldGuard browser extension was dismantled after it was found harvesting sensitive data from crypto users, putting wallet and account information at risk. Th...
ShieldGuard browser-extension data-harvesting malware
Malware ActivityAbout this happening: A malicious ShieldGuard browser extension was dismantled after it was found harvesting sensitive data from crypto users, putting wallet and account information at risk. Th...
Perplexity Comet prompt-injection research shows agentic browsers can be trained into phishing traps
Technical Analysis
H score25
First: 11.03.2026 18:38
Last: 11.03.2026 18:38
Sources 1
About this happening:
Perplexity's Comet AI browser is the focus of a technical analysis thread showing how prompt injection and malicious URLs can steer an agentic browser into data...
Perplexity Comet prompt-injection research shows agentic browsers can be trained into phishing traps
Technical AnalysisAbout this happening: Perplexity's Comet AI browser is the focus of a technical analysis thread showing how prompt injection and malicious URLs can steer an agentic browser into data...
QuickLens and ShotBird malicious Chrome extension update chain
Malware Activity
H score34
First: 09.03.2026 12:28
Last: 09.03.2026 12:28
Sources 1
About this happening:
The QuickLens and ShotBird Chrome extensions have become malicious after ownership transfer, turning trusted add-ons into a delivery path for code injection and data t...
QuickLens and ShotBird malicious Chrome extension update chain
Malware ActivityAbout this happening: The QuickLens and ShotBird Chrome extensions have become malicious after ownership transfer, turning trusted add-ons into a delivery path for code injection and data t...
Timeline
-
25.06.2026 17:12 2 articles · 20d ago
Adblock for YouTube exposes dormant remote-controlled script injection path
Technical Analysis UpdateIsland identified a dormant remote-controlled script injection path in Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), a Chrome extension with more than 10 million installs and a Featured badge, that could enable arbitrary JavaScript execution on any website after a single server-side configuration change. The researchers said the code path centers on a bespoke scriptlet rule named trusted-create-element and a youtube.com check that can be bypassed by placing the string anywhere in a URL, while noting they saw no evidence that malicious payloads were distributed to users.
Show sources
- Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability — thehackernews.com — 25.06.2026 17:12
- Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability — thehackernews.com — 25.06.2026 17:12