SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click
I was going through the SelectorsHub code, id:ndgimibanhlabgdgjcpbbndiehljcpfh the XPath extension with about 400k users, and noticed it pulls ads from its own server and opens them in a background tab. You don’t click anything. Every couple of days the side panel pops up a “community link” and says “100% Safe, No Spam, No Malware.” Five seconds later the tab opens by itself. The URL isn’t in the extension. Their server picks it, and while I was analysing the extension the links changed three times with no extension update. On install and update it skips the popup and just opens whatever the server sends. The store page says they collect no data. The code still pings them daily, and the extension reads all your cookies to find one of its own instead of just fetching its own cookie value. Another weird finding: there’s a hidden Fix Selector button that sends the selector to shubads[.]testcasehub.net. VirusTotal – Domain – shubads.testcasehub.net That host now redirects to a gambling site, blomehairdryers[.]com. Nothing gets run today because the reply is HTML, but that’s the server the eval path trusts. Looks like adware, not password theft. I wouldn’t leave it on a work browser, especially since this is a tool used by devs and tech people browsing protected endpoints in a company. Write-up: https://malext.io/reports/RedirectorsHub/ submitted by /u/Huge-Skirt-6990 [link] [comments]Technical Information Security Content & DiscussionRead More