The Nigerian Communications Commission (NCC) has advised Nigerians to remove five malicious Google Chrome Extensions from their phone and laptop to steal users’ data.
The NCC announced this in a press release posted on its website and identified five Google Chrome Extensions for Nigerians.
According to the commission, the extensions surreptitiously track online browser activities and steal users’ data.
The five malicious extensions which the McAfee Mobile Research Team discovered include:
-
Netflix Party;
-
Netflix Party 2;
-
Full Page Screenshot Capture Screenshotting;
-
FlipShope Price Tracker Extension, and
-
AutoBuy Flash Sales.
According to the Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT), many Nigerians have downloaded the five Google extensions.
NCC-CSIRT said 800,000 people have downloaded Netflix Party, 300,000 people have downloaded Netflix Party 2, Full Page Screenshot Capture Screenshotting with 200,000 downloads, FlipShope Price Tracker Extension with 80,000 downloads, and AutoBuy Flash Sales with 20,000 downloads.
According to NCC-CSIRT, the five google chrome extensions identified have a high probability and damage potential, have been downloaded more than 1.4 million times, and serve as access to steal users’ data.
Part of the advisory from NCC reads: “The users of these chrome extensions are unaware of their invasive functionality and privacy risk.
Malicious extensions monitor victims’ visits to e-commerce websites and modify the visitor’s cookie to appear as if they came through a referrer link.
Consequently, the extensions’ developers get an affiliate fee for any purchases at electronic shops.”
NCC also stated that although the google team removed several browser extensions from its Chrome Web Store, keeping malicious extensions out may be difficult.
The NCC-CSIRT, thus, recommended that telecom consumers observe caution when installing any browser extension.
The warning continues: “These include removing all listed extensions from their chrome browser manually.
“Internet users are to pay close attention to the promptings from their browser extensions, such as the permission to run on any website visited and the data requested before installing it. “
Although some extensions are seemingly legit, due to the high number of user downloads, these hazardous add-ons make it imperative for users to ascertain the authenticity of extensions they access.”
Google Chrome extensions are software programmes that can be installed into Chrome in order to change the browser’s functionality.
This includes adding new features to Chrome or modifying the existing behaviour of the program itself to make it more convenient for the user.
They serve purposes such as block ads, integration with password managers and sourcing coupons as items sent to a shopping cart.