History of an announced crisis. The Pirate Bay turned the Web upside down with its crypto mining test to eliminate advertising, but that is just the tip of the iceberg. Within hours, dedicated solutions emerged to interrupt miners on pages and services, but the "me too" dynamic has now reached extensions for Google Chrome. The first case is SafeBrowse, which had more than 140,000 users before the discovery...

First Chrome Extension with an Integrated Cryptominer Detected
SafeBrowse

Imagine a program or service with hundreds of thousands of users... or why not millions. Any measure of popularity is built on good support, fulfilled promises, and trust. That's when some developers decide to "bend" a bit of that trust to their advantage, and it backfires. The Pirate Bay's Coinhive-based test caused an uproar not because the site is seeking an alternative funding method, but because it never consulted its users. Now that the situation has been "whitened", so to speak, opinions are a bit more divided, but that only applies to The Pirate Bay. From the beginning we knew it was a matter of time before JavaScript miners multiplied, and today it's SafeBrowse's turn.

First Chrome Extension with an Integrated Cryptominer Detected
I think there is no doubt.

Basically, we are facing the first documented case of a Google Chrome extension with an integrated cryptominer. With more than 140,000 users, reports of high CPU usage were not long in coming. The people at BleepingComputer obtained a copy of the extension (the affected version is 3.2.25), viewed its code, and there appear multiple references to Coinhive. On a computer with a Core i5 processor, the miner took on average 61 percent of available resources, with peaks reaching 100 percent. Once the extension was removed, Chrome's behavior regarding the processor returned to normal.

What do SafeBrowse developers say? That the extension has not received any updates in months, and that the presence of the miner is the work of an attack. On the other hand, its record is not exactly clean: SafeBrowse was already involved in November 2015, when a group of researchers detected tracking features that operated without user consent. Google cut it off and removed SafeBrowse from the store, but if it's so easy to insert malicious code into Chrome extensions, it will need to implement much deeper changes.

BleepingComputer