A new malware service promises to skip Google’s review process and get your malware straight into the Chrome Store


  • Russian Hackers Sell Chrome Extension Service That Bypasses Google Store Moderation
  • Malicious add-on spoofs legitimate websites with full-screen iframes to steal credentials
  • Varonis advises strict enterprise permission list and auditing of consumer extensions to protect them

Russian hackers are selling a service that allows other criminals to spoof legitimate websites, trick victims into revealing login details, or possibly even make fraudulent bank transfers.

A threat actor alias ‘Stenli’ (Stanley) recently started offering a service that basically guarantees that a malicious Chrome extension will “pass Google Store moderation” and land in the browser’s add-on repository.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top