I discovered some obfuscated code in the PDF Toolbox extension which is used by more than 2 million people. The code is meant to download a “config” file from serasearchtop[.]com after which it will run some functions according to this configuration. I didn’t see a non-empty configuration yet. However, given the specific call pattern used, I’m mostly certain that the idea here is injecting arbitrary JavaScript code into every website when it loads.
I suspect that this is part of the extension’s monetization strategy, most likely goal being injecting ads into all websites. But it could really be anything, and it might be spying on people as they enter their online banking credentials or credit card numbers.
palant.info/2023/05/16/malicio…
Malicious code in PDF Toolbox extension
PDF Toolbox extension (used by more than 2 million users) contains obfuscated malicious code, allowing serasearchtop[.]com website to inject arbitrary JavaScript code into all websites you visit.Almost Secure
Talon
in reply to Dan Gero • • •Dan Gero
in reply to Talon • • •Andre Louis
in reply to Dan Gero • • •Talon
in reply to Dan Gero • • •Dan Gero
in reply to Talon • • •reshared this
Andre Louis and victor tsaran reshared this.
Andre Louis
in reply to Dan Gero • • •Dan Gero
in reply to Andre Louis • • •Talon
in reply to Andre Louis • • •Andre Louis
in reply to Talon • • •Andre Louis
in reply to Dan Gero • • •Dan Gero
in reply to Andre Louis • • •