Protect.Computer
NEWS

1.6 Million Users Urged to Remove ModHeader Browser Extension

· 1 min read · Privacy tracking Device safety
1.6 Million Users Urged to Remove ModHeader Browser Extension

Google and Microsoft have removed the ModHeader browser extension from their official stores after security researchers at Stripe OLT discovered dormant tracking code hidden inside it. ModHeader is a popular tool used by approximately 1.6 million people — around 900,000 on Chrome and 700,000 on Edge — that lets developers and power users customize how their browser sends and receives web requests.

The hidden code, if activated, was designed to record every website you visit, bundle that list with a device fingerprint, and transmit it daily to a third-party server. Fortunately, the tracking was never switched on — an empty setting kept it inactive — and there is no evidence that any browsing data was actually collected or sent. However, the code existed in the version distributed through official stores, so removing it is the right call. Users who had ModHeader installed and entered sensitive information like API keys or login session cookies should take an extra step and rotate those credentials.

How to check if you’re affected

Affected versions of ModHeader include all copies installed from the Chrome Web Store or the Microsoft Edge Add-ons store up until the extension was removed. To check: in Chrome or Edge, click the puzzle piece icon in the top-right corner of your browser and look for ModHeader in your list of extensions. If you see it, click the three-dot menu next to it and choose “Remove from browser.” If you used ModHeader to work with authentication tokens or API keys, rotate those credentials as a precaution.

Sources

Related reading