Skip to main content

A sneaky extension for Chrome, Firefox prevents its removal, hijacks browser

Chrome Apps

Internet security firm Malwarebytes recently discovered that a pair of extensions will not only hijack Chrome and Firefox, but will block any attempts to remove them from these two browsers. The version found in Chrome is a forced extension resulting from web pages that trick visitors into installing the extension via a JavaScript-based popup. The Firefox version stems from advertisements pretending to be an official manual update requirement warning posted by Mozilla. 

“Tiempo en colombia en vivo” is the name of the invading Chrome extension. Malwarebytes doesn’t provide any specifics about what this extension actually does to Chrome but presumably, it completely hijacks the browser to push technical support scams, drive click numbers on specific websites, or completely hijack web searches. The company’s listing says it could spy on your web browsing activities too. 

It’s essentially force-installed by hijacking the browser on websites supporting the extension. If you try to leave the page, a popup appears asking to add an extension for exiting the page. If you select cancel, another popup will appear with an additional tick box that says “Prevent this page from creating additional dialog.” Check the box, hit “OK,” and the browser goes full screen with a popup revealing the name of the extension that is supposedly distributed through the Chrome Web Store. 

Thinking it’s legit, Chrome users install the extension. But the problems only get worse for there. When Chrome users attempt to access the in-browser extensions section, they are directed to a fake extension page that doesn’t list the installed, offending extension. Because this page is internal, disabling JavaScript doesn’t fix the problem. The only way to regain control is to add “–disable-extensions” after chrome.exe in the shortcut command line (which disables all extensions), or rename the “1499654451774.js” file in the extensions folder. 

Meanwhile, the Firefox extension takes a different route. Victims will see a web-based advertisement warning that Firefox requires a manual update. Taking the bait, they inadvertently install the offending extension, which prevents them from accessing the internal “about:addons” page by closing the tab. To remove the extension, you can restart Firefox in safe mode. Extensions are not active in this state, thus you can remove any add-on before restarting the browser. 

“If you are kept on a Firefox tab by JavaScript(s) that keep popping up with prompts, and you are unable to close the window in the usual way, you can terminate Firefox by using Task Manager,” the company states. “When you restart Firefox, it will not be able to restore the session for that tab.” 

Believe it or not, Task Manager is your best friend in Windows. Simply type CTRL+ALT+DEL, and you can open the Task Manager window to force-close any browser tab that refuses to close. You don’t need to install anything to escape the clutches of a malicious web page. Even more, Google and Mozilla absolutely do not send warning advertisements on web pages to manually upgrade your browser. Updates are typically performed behind the scenes. 

Editors' Recommendations

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Chrome extensions with 1.4M users may have stolen your data
Google Chrome icon in mac dock.

McAfee researchers have discovered various Google Chrome extensions that steal browsing activity, with the add-ons racking up more than a million downloads.

As reported by Bleeping Computer, threat analysts at the digital security company have come across a total of five such malicious extensions.

Read more
Google Chrome extensions are failing, and $8,000 is on the table for a fix
A mouse pointer hovering over the CrankWheel Chrome Eextension.

There seems to be some mysterious problem affecting certain Chrome extensions, but it's intermittent enough that it hasn't yet been solved. The problem is annoying enough that one developer has posted two $4,000 bug bounties and created an Upwork job listing that pays up to $150 per hour. These incentives might inspire others to help track down and fix the bug.

First spotted by TechRadar and described in detail in a blog post written by Jói Sigurdsson, founder and CEO of the CrankWheel screen-sharing extension for the Google Chrome browser, the bug is related to a failure to trigger an action when the extension's icon is clicked on the toolbar. Since this is frequently how an extension is used, it's a crippling error. Unfortunately, the problem is difficult to recreate and is estimated to impact only 3% to 5% of those that have affected extensions installed.

Read more
Firefox just gave you a great reason to ditch Chrome for good
A symbol of the Mozilla Firefox logo.

Mozilla Firefox has just made changes to its browser, making an existing feature available by default to all users. The tool is called Total Cookie Protection, and thanks to it, Firefox now calls itself "the most private and secure major browser available across Windows, Mac, and Linux."

Whether Firefox is really the best browser remains to be seen, but Total Cookie Protection certainly kicks things up a notch where privacy is concerned. Will it be enough to help Firefox pull ahead of the competition?

Read more