logoalt Hacker News

honzaiktoday at 2:16 PM1 replyview on HN

it apparently scans for something like "PQC Checker", an extension for checking if TLS connection is PQC-enabled? how is that a spam extension (and thats just a random one i saw)


Replies

Aurornistoday at 2:20 PM

Probably compromised extensions or misleading extensions.

It’s common for malware extensions to disguise themselves as something simple and useful to try to trick a large audience into installing them.

That’s why the list includes things like an “Islamic content filter” and “anti-Zionist tagger” as well as “neurodivergent” tools. They look for trending topics and repackage the scraper with a new name. Most people only install extensions but never remove them if they don’t work.

show 3 replies