Closed Bug 1528761 Opened 5 years ago Closed 5 years ago

Extension block request: Rogue Youtube downloaders and related add-ons

Categories

(Toolkit :: Blocklist Policy Requests, task)

task
Not set
normal

Tracking

()

RESOLVED FIXED

People

(Reporter: Fallen, Assigned: Fallen)

Details

(Whiteboard: [extension])

GUIDs:

pohhpifegcbplaijeeonlbkjgocfgjbf@chrome-store-foxified-18573537
pohhpifegcbplaijeeonlbkjgocfgjbf@chrome-store-foxified-570932499
aackamlchlgmalkmcphbhhcjebbpnfdf@chrome-store-foxified-233164420
pohhpifegcbplaijeeonlbkjgocfgjbf@chrome-store-foxified-1808417494
nnfhjlgginbfdejaajhbboeemajpjgfp@chrome-store-foxified-699139867
dilkapnoekabmkkhhdlpnpfgjcmddlia@chrome-store-foxified-1808417494
dilkapnoekabmkkhhdlpnpfgjcmddlia@chrome-store-foxified-1190639722
nnfhjlgginbfdejaajhbboeemajpjgfp@chrome-store-foxified-2745518014
fibaefnljghpmdibfkhnlaniblfkkndi@chrome-store-foxified-1955364993
dilkapnoekabmkkhhdlpnpfgjcmddlia@chrome-store-foxified-1516694386
generated-rk4dtanssk56goquir78sz@chrome-store-foxified--1594555229
nnfhjlgginbfdejaajhbboeemajpjgfp@chrome-store-foxified-1388315457
oaoebpgbkehlcdggaeeohgfpopdhjell@chrome-store-foxified-1823310541
fibaefnljghpmdibfkhnlaniblfkkndi@chrome-store-foxified--1031675095
ancjheohbkbnkgcmfaldcaepoeeplkgh@chrome-store-foxified-1823310541
generated-lwcbpuj27wcknyyl6pkap7@chrome-store-foxified-1823310541
generated-bmtr2hbgikv399aj6aeycd@chrome-store-foxified-1823310541
generated-8w9odie82h2ugbsrofooj3@chrome-store-foxified-1823310541
{4170faaa-ee87-4a0e-b57a-1aec49282887}
{b66dd4bc-7f5e-41d9-bc43-84c5736d0c87}
{507ad1fb-08ae-43ac-a596-fd5b6e7dea9a}
{8bf85207-66df-4eb7-b913-ac162498c687}
{b063895a-8077-452d-b049-ebc20a39f882}
{5776bd90-3d09-43b5-a769-8da373e9820f}
{f6bdce44-3d5a-4f88-9a64-e39fcb4f0717}
{1c22e687-6a02-440c-a6d5-c1ccaf520e10}
{f7be824f-7287-466a-8590-2f48007a223b}
{89ffc0b4-97f7-447c-bd6f-9c519b0188bd}
{3a67084b-c231-4b4b-a924-ffa741f90921}
{fac8b1d0-f321-491d-9234-c40d89b3660d}
{a8053a83-8d1a-4f0e-9f88-d31cfe00cf83}
{d10fa57e-37d3-43d3-39f8-e6d5b2a7759d}
youtube_downloader@downloaders.xyz
savetube_downloader@savetube.co
{95a8a08c-53a8-7e1d-5a80-f1a5cd4751bf}
{5037bd74-c23b-4bbf-8865-6b5a09e07342}
ytdownloader@ytdownloader.org
youtube_grabber@utubegrabber.co
youtube_download_express@free-downloader.online
{830c558c-70f0-4b07-95f1-8e06ad34ee2c}
{e4d93c37-1299-452f-9b60-adee15ad3802}
googlemaps@search

Block severity: hard

Reasons: Malicious add-ons injecting remote scripts and exfiltrating data for monetization purposes. Some of the add-ons are masking themselves as legit add-ons and using various obfuscation tactics to hide their injections.

The block has been staged. Andreas, can you review and push?

Flags: needinfo?(awagner)
Assignee: nobody → philipp
Status: NEW → ASSIGNED
Flags: needinfo?(jorge)
Flags: needinfo?(jorge)

Done.

Note for this bug (the blocklist pattern already respects this):

The following 4 GUIDs have already been blocked before:

youtube_downloader@downloaders.xyz
ytdownloader@ytdownloader.org
youtube_grabber@utubegrabber.co
youtube_download_express@free-downloader.online

Status: ASSIGNED → RESOLVED
Closed: 5 years ago
Flags: needinfo?(awagner)
Resolution: --- → FIXED

Just to be sure that it's not another occurrence, I suggest somebody take a look at this addon https://addons.mozilla.org/fr/firefox/addon/google-translate-in-page/
Sorry, I have no idea if the addon content is suspicious or not.

I felt on this issue, following this https://blocked.cdn.mozilla.net/f2483d7d-1895-4ae6-9901-7321e59062a6.html

thx

Can you file a new bug for this? We can investigate this add-on separately then.

Type: enhancement → task
You need to log in before you can comment on or make changes to this bug.