Your Adblock for YouTube is a ticking time bomb for your bank account
Over 10 million users just found out their favorite Adblock for YouTube extension is basically a Trojan horse waiting for a remote signal to swipe their credentials. It is truly heartwarming to see how much we trust random code from the Chrome Web Store.
Security researchers at Island discovered that the popular extension Adblock for YouTube contains a hidden mechanism capable of executing arbitrary JavaScript on any website you visit. While it technically hides ads, the code includes a remote instruction set that allows the developer to push updates without going through any store review process.
The extension uses a custom rule dubbed trusted-create-element, which lets it bypass standard protections to inject <script> tags into your browser. Even more delightful, the extension checks for the string youtube.com in the URL but fails to verify the actual hostname. This means an attacker could craft a malicious link like bank.com/search?q=youtube.com to trigger the execution of the code on your financial accounts.
Although there is no concrete proof that the developers have pulled the trigger on a massive data heist yet, the "kill switch" is currently sitting dormant on their servers, ready to be flipped at any moment. Island also identified a cluster of similar shady extensions—Adblock for Chrome, Adblock for You, and AdBlock Suite—which have already been purged from the Chrome Web Store for being malicious.
Total lack of oversight is a feature, not a bug, in an ecosystem where "free" tools are just harvested data waiting to happen. Apparently, convenience is worth more than a digital identity these days.
Source: Island
Comments
Help shape the next version: Add context or suggest a correction. AI review can add points toward a rewrite. Reviews and updates may take time; a full meter does not guarantee a new version.