An extension I used almost every day was bought by a new owner and loaded up with spyware. It happened in 2024, but Google ...
"Under New Management" keeps an eye on the Chrome Web Store, looking for new developer names that show up when extensions are sold off.
Reddit users seem to have identified the problem.
Threat actors are publishing clean extensions that later update to depend on hidden payload packages, bypassing marketplace ...
Malicious JavaScript code delivered by the AppsFlyer Web SDK hijacked cryptocurrency, potentially in a supply-chain attack.
More fun than it should be, honestly.
How can an extension change hands with no oversight?