ON AIR NOW

LISTEN NOW

Weather

cloudy-day
77°
Partly Cloudy
H 77° L 49°
  • cloudy-day
    77°
    Current Conditions
    Partly Cloudy. H 77° L 49°
  • cloudy-day
    50°
    Morning
    Partly Cloudy. H 77° L 49°
  • cloudy-day
    62°
    Afternoon
    Partly Cloudy. H 65° L 36°
LISTEN
PAUSE
ERROR

Krmg news on demand

00:00 | 00:00

LISTEN
PAUSE
ERROR

Krmg traffic on demand

00:00 | 00:00

LISTEN
PAUSE
ERROR

Krmg weather on demand

00:00 | 00:00

Google pulls two Chrome extensions for pushing malware

If you use Google's popular web browser Chrome, you may want to think twice before downloading your next extension. The company recently pulled two products from its extension store after they started pushing malware on their users.

The story starts with Amit Agarwal, a tech blogger who created the Add to Feedly extension to augment the popular RSS service. In a blog post, Agarwal says someone offered to buy his extension after it gained around 30,000 Chrome users. "It was a 4-figure offer for something that had taken an hour to create and I agreed to the deal." (Via Digital Inspiration)

A few months after the purchase, Add to Feedly's new owners quietly updated the extension with adware. The once-useful add-on now injected malicious ads onto webpages, replacing links and confronting users with pop-ups. (Via OMG Chrome)

After Add to Feedly's woes went public, a writer for Ars Technica shared a similar experience he had with a different Chrome extension.

"About a month ago, I had a very simple Chrome extension called 'Tweet This Page' suddenly transform into an ad-injecting machine and start hijacking Google searches. ... The extension only started injecting ads a few days after it was installed in an attempt to make it more difficult to detect."

The Wall Street Journal notes in both cases malware purveyors took advantage of an existing extension's user base and Chrome's lax security standards. "Google doesn't review changes to the code of Chrome extensions, and Chrome allows extensions to be updated and pushed to users' computers automatically."

Google has since removed both applications from its store, but the practice of spreading malware through Chrome extensions is still a threat.

One developer for the Chrome extension Honey recently held an Ask Me Anything on Reddit, revealing the add-on had received numerous buy-out offers from malware companies and data collection firms. According to Google, Honey has about 300,000 users.

And Quartz points out Chrome's security team still mostly relies on user reviews to police their extension store. "Google looks like it's taking a more proactive role in enforcement, but it is still a long way from Apple's in-house regulatory commission, or even Firefox's less-rigorous editorial review."

Back in December, Google announced it will limit add-ons to a single function, getting rid of Trojan horse extensions which deliver ads in addition to their normal use. The policy goes into full effect in June.

- See more at Newsy.com

Read More
VIEW COMMENTS

There are no comments yet. Be the first to post your thoughts. or Register.

  • A top Republican Oklahoma House leader is back to the drawing board trying to shore up the state's budget and generate funding for a teacher pay raise. Majority Floor Leader Jon Echols said Friday work already is underway on potential changes to a broad tax-increase plan. Echols says he's remaining in touch with the governor's office and that he's working on potential 'tweaks' to the plan that could garner the necessary 76 votes in the House.  A sweeping package of tax hikes on tobacco, fuel, alcohol and oil and gas production fell five votes short in the House after an eight-week special session. Governor Mary Fallin vetoed a backup budget plan approved by lawmakers that would have further slashed agency budgets and implored them to return for a second special session.  No date has been set.
  • Lindsay Weiss once lost her cellphone and got it back, so she and a friend knew what they had to do when they discovered a camera under a pew during a festival in the Nevada desert - even though it meant giving up their coveted, shady seat for a musical performance. The friends snapped a quick selfie and took the device to the lost-and-found, so the owner could claim it and the pair could “forever be a part of their journey,” Weiss said. “Losing something out there on the playa makes its mark on your trip,” she said of the sprawling counterculture gathering known as Burning Man. “Kinda makes you feel like a loser.” Cameras and IDs are among the more common belongings that end up in the lost-and-found after the event billed as North America’s largest outdoor arts festival. Other items left behind in the dusty, 5-square-mile encampment include shoes, keys, stuffed animals - even dentures. Still missing are a marching band hat with gold mirror tiles, a furry cheetah vest, a headdress with horns and a chainmail loincloth skirt. “As of mid-November, we’ve recovered 2,479 items and returned 1,279,” said Terry Schoop, who helps oversee the recovery operation at Burning Man’s San Francisco headquarters.
  • An 86-year-old Philadelphia woman allegedly pushed her walker into a bank Tuesday afternoon and . >> Read more trending news Bank employees told police the woman, identified as Emily Coakley, brandished a gun and demanded $400, CBS Philly reported. It didn’t take long for the police to arrive, and they arrested the senior citizen. Authorities say the woman had a .38-caliber revolver. They said the gun was not loaded, but, she did have bullets in her purse, according to The Morning Call. University of Pennsylvania police responded to a robbery call at the TD Bank at 3735 Walnut St. around 2 p.m. Tuesday. Coakley has been charged with aggravated assault, robbery and other related offenses. According to witnesses, Coakley had visited the bank the day earlier and was under the impression she had been shorted $400 from her withdrawal that was the specific total she demanded from the teller. Her family later arrived and tried to defuse the situation. Despite this, people near the bank weren’t happy. “Someone could have got shot, even accidentally. You have to have concerns. People bring their kids here,” customer Will Duggan told Fox 29 in Philadelphia. The Morning Call said she did not offer comment as police escorted her from the bank.
  • South Africa’s Supreme Court of Appeal increased the jail sentence for former Paralympian Oscar Pistorius to 13 years, 5 months, the reported Friday. Pistorius was originally sentenced to six years in prison for the 2013 murder of his girlfriend, Reeva Steenkamp.  'The sentence imposed by the … [High Court] with respect to murder is set aside and substituted with the following –- the respondent’s imprisonment for 13 years and five months,' Justice Legoabe Willie Seriti said.  He said Pistorius should have been sentenced to 15 years, but the Supreme Court of Appeal took into account the time he had already served, News24 reported.  Pistorius was arrested on Valentine’s Day in 2013 –- the day of the killing. North Gauteng High Court Judge Thokozile Masipa initially sentenced Pistorius to five years for culpable homicide in 2014, News 24 reported. Pistorius served only 10 months of the five-year sentence in prison before being released and put under house arrest. The state appealed the culpable homicide conviction, and it was later replaced with murder by the Supreme Court of Appeal in 2016, and Masipa handed down a six-year jail term, News24 reported. Previously, the six-time Paralympic gold medallist had made history by becoming the first amputee sprinter to compete at the Olympics, in 2012 in London, running on prosthetic 'blades.” He had his legs amputated below the knee as a baby, the BBC reported.
  • In September of 2016, enough signatures were certified on an initiative petition to put medical marijuana on a ballot in Oklahoma, but so far, Governor Mary Fallin has not designated a date for voters to decide the issue. Members of Oklahomans for Health, an advocacy group which favors State Question 788, aren’t happy with the delay, and have begun a campaign to turn the heat up on the governor’s office. Shawn Jenkins, a spokesman for Oklahomans for Health, spoke with KRMG on Wednesday. “We have started a phone campaign and an email campaign that is currently going, that started this week,” Jenkins said, “specifically requesting that it be put on the ballot - and some people are a little bit more not requesting, but demanding that it be put on the ballot - and not just on the ballot, not in November, because that’s too late. This issue was petitioned in 2016.” But the language of the ballot title became an issue when then state Attorney General Scott Pruitt removed the word “medical” from it, which sparked a court battle which restored it, but delayed the issue long enough to prevent a vote that year. Now 2017 has come and gone, and the governor still hasn’t acted, though she could do so at her discretion. Jenkins, a veteran who served with the 101st Airborne Division, suffers glaucoma and also has a son with a rare disease. When KRMG asked him why he advocates for medical marijuana, he discussed the potential benefits for himself, his family, and his fellow veterans. But first, he talked about his rights. “I first got involved with advocacy for it because of being so conservative in my philosophy, and individual rights, and aspects of freedom and liberty,” he told KRMG. If the governor doesn’t call for an election, the issue will still appear on Oklahoma ballots, but not until November of 2018.