Closed
Bug 1504619
Opened 6 years ago
Closed 6 years ago
"Google Translate with Right Click" add-on is spying on users
Categories
(Toolkit :: Blocklist Policy Requests, defect)
Tracking
()
RESOLVED
FIXED
People
(Reporter: david, Assigned: TheOne)
References
()
Details
Attachments
(1 file)
26.22 KB,
application/x-xpinstall
|
Details |
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:63.0) Gecko/20100101 Firefox/63.0
Steps to reproduce:
Install "Google Translate with Right Click" add-on: https://addons.mozilla.org/en-US/firefox/addon/google-translator-right-click/
Actual results:
A hook is installed that can send data from my computer to arbitrary destinations.
Expected results:
No such hook should be installed.
I am reporting this issue because I believe that the "Google Translate with Right Click" add-on has been compromised. It was recently updated requesting permissions for all content on all pages. When I checked the files in the updated add-on, I saw that it nows has a `bgd.js` file that is run in the background on every page. This script is minified and obsfucated, and it appears to create a hidden iframe on every page. When a page sends a message to the hook in this add-on, the add-on appears to read files from the user's computer and send them to the destination specified in the message.
Updated•6 years ago
|
Component: Untriaged → Blocklist Policy Requests
Flags: needinfo?(jorge)
OS: Unspecified → All
Product: Firefox → Toolkit
Hardware: Unspecified → All
Updated•6 years ago
|
Assignee: nobody → awagner
Flags: needinfo?(jorge)
Assignee | ||
Comment 1•6 years ago
|
||
Let's block the add-on due to the malicious/deceptive behavior. The malicious code looks dead in the latest version, but there are clones using similar or same code. IDs to block:
{b384b75c-c978-4c4d-b3cf-62a82d8f8f12}
{b471eba0-dc87-495e-bb4f-dc02c8b1dc39}
{36f623de-750c-4498-a5d3-ac720e6bfea3}
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Assignee | ||
Comment 2•6 years ago
|
||
The block has been staged. Jorge, can you please review and push?
Flags: needinfo?(jorge)
Comment 3•6 years ago
|
||
Review and approved.
Status: ASSIGNED → RESOLVED
Closed: 6 years ago
Flags: needinfo?(jorge)
Resolution: --- → FIXED
Comment 4•6 years ago
|
||
Thanks.
There is a fresh extension from a new developer that provides the same functionality:
https://addons.mozilla.org/firefox/addon/google-translate-within-page/
Is it also malware or it is fine?
You need to log in
before you can comment on or make changes to this bug.
Description
•