Wednesday, May 21, 2025
HomeComputer SecurityChrome Extension That Steals Credit Cards Numbers Detected On Web Store

Chrome Extension That Steals Credit Cards Numbers Detected On Web Store

Published on

SIEM as a Service

Follow Us on Google News

A chrome extension that still available on Chrome Web Store steals the payment card information from website forms visited by the users.

The extension found to be active form February 2018, and the extenstion hidden from regular searches and will be available only through the link that attackers use to spread.

Malicious extension named Reader Flash distributed through injection method, attackers use to infect websites with malicious javascript which detects the browser used by victims and indicates to install flash and redirect them to download the extension.

- Advertisement - Google News

According to Elevenpaths analysis, the extension embeds simple function to all the websites visited by the user and exploits API functionality webRequest.onBeforeRequest and intercept the user’s form submission.

The injected scripts regularly monitor credit card numbers by having regular expressions in the code for Visa (vvregex), MasterCard (mcregex), etc.”In case of any of the data included in the request is a card number, these numbers –encoded in JSON– will be sent to the attacker through an AJAX request.”

Reader Flash extension found installed more than 400 times and the extension will be available only through the link and not through commom search.”The infrastructure has not been massively spread so far.”

The extension has been reported by Elevenpaths to Google to remove the extension from the Chrome store.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read

Mega vs Dropbox: Most Important Cybersecurity Consideration in the Cloud

A New Banking Malware Disguises as Security Module Steals Your Banking Credentials

Bittrex Cryptocurrency Exchange Delist the Bitcoin Gold After They Declined to Pay 12,372 BTG for Cyber Attack

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Critical Vulnerability in Palo Alto GlobalProtect Gateway & Portal Enables Remote Code Execution

Palo Alto Networks has assigned the vulnerability a LOW severity rating but urges administrators to apply...

Hazy Hawk Targets DNS Vulnerabilities to Hijack Cloud Resources and Spread Malware

The threat actor gained attention in February 2025 after successfully hijacking a subdomain of...

Critical VMware ESXi & vCenter Flaw Allows Remote Execution of Arbitrary Commands

VMware by Broadcom has released critical security updates to address multiple severe vulnerabilities affecting...

Accenture Files Leak – New Research Reveals Projects Controlling Billions of User Data

A new research report released today by Progressive International, Expose Accenture, and the Movement...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hazy Hawk Targets DNS Vulnerabilities to Hijack Cloud Resources and Spread Malware

The threat actor gained attention in February 2025 after successfully hijacking a subdomain of...

More_Eggs Malware Uses Job Application Emails to Distribute Malicious Payloads

The More_Eggs malware, operated by the financially motivated Venom Spider group (also known as...

Hackers Use Weaponized RAR Archives to Deliver Pure Malware in Targeted Attacks

Russian organizations have become prime targets of a sophisticated malware campaign deploying the Pure...