logoalt Hacker News

proactivesvcstoday at 12:02 AM2 repliesview on HN

"In terms of implementation, the most interesting one is “Іron Wаllеt” (the I, a, and e are Cyrillic). Three seconds after install, it fetches the phishing page’s URL from the first record of a NocoDB spreadsheet and opens it [...] The API key had write access, so I wiped the spreadsheet."


Replies

methodisttoday at 12:32 AM

The extension is actually still up: hxxps://addons[.]mozilla[.]org/en-US/firefox/addon/%D1%96ron-w%D0%B0ll%D0%B5t/

thephybertoday at 6:46 AM

Did you just admit to a CFAA violation?

show 1 reply