Google and Microsoft removed the ModHeader browser extension from the Chrome Web Store and Edge Add-ons store after researchers found dormant code in the official signed extension that could collect users’ browsing domains and prepare them for exfiltration. Analyses of versions 7.0.17 and 7.0.18 found a built-in pipeline that extracted domains from visited URLs, encrypted them with AES-GCM, stored up to 1,000 entries locally in IndexedDB or browser storage, and staged them for upload to api.stanfordstudies[.]com/app/log. Researchers said the internal allow-list controlling the collector was empty, and they reported no evidence that browsing-domain data was actually transmitted.
The extension had an estimated 1.6 million users across Chrome and Edge and already held broad permissions, raising concern that the dormant capability could have been activated later through a routine signed update without prompting users for new access. Separate reporting said the extension also sent active telemetry for install, update, and uninstall events to extensions-hub[.]com, while a script running on every page logged request metadata locally in plaintext. Microsoft reportedly removed the Edge listing first, and Google later flagged the Chrome version as malware and pulled it, underscoring the supply-chain risk posed by trusted, high-permission browser extensions.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Stripe OLT researchers said ModHeader version 7.0.18 contained a hidden spyware SDK and assessed with low confidence that a Chinese-speaking threat actor was responsible. They cited Chinese-language strings in the code and the use of Lark-routed emails as supporting indicators.
Researchers found that the official ModHeader browser extension contained a dormant pipeline capable of collecting browsing domains, encrypting and storing them locally, and preparing them for upload to api.stanfordstudies.com. They reported that the internal allow-list was empty and found no evidence that browsing-domain data was actually exfiltrated in the analyzed builds.
Google later removed ModHeader from the Chrome Web Store and one report says it flagged the extension as malware. A source explicitly dates the Chrome listing removal to July 10.
Microsoft removed the ModHeader extension from its store after the dormant collector was discovered in the official extension. One report explicitly states the Edge listing was removed on July 3.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcecysecurity.news
Open sourcethehackernews.com
Open sourcestripeolt.com
Open sourceaydinnyunus.github.io
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.