[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$flV9okdF0fYo0Ic7dZnULYfjJATvS5VqrBR2_sTyOkT8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"476182a3-6a91-4d75-93d1-d8bd1292adee","dormant-data-collector-found-hidden-in-popular-browser-extension-used-by-16-million","0d4e79e2-33e8-447a-92ab-efc66ee84ee4","Dormant Data Collector Found Hidden in Popular Browser Extension Used by 1.6 Million","The ModHeader incident illustrates a classic supply chain risk: a widely trusted, legitimate browser extension was found to contain hidden functionality capable of harvesting browsing history, even if not yet activated. The presence of a dormant data collector — disabled only by an empty allow-list that could be populated remotely at any time — demonstrates how malicious or compromised code can lie in wait within software users already trust. Compounding the risk, the extension logged real request metadata in plain text to local storage and phoned home to a separate domain on lifecycle events, exposing users to data leakage and covert tracking. This matters because browser extensions operate with significant privileges inside the browser, making them a high-value target for supply chain attacks, insider threats, and code injection. Organizations and individuals often overlook extensions as an attack surface, creating a gap that threat actors are increasingly exploiting.","**Immediate actions:**\n- Audit all installed browser extensions across your organization and remove any that are unverified, unused, or recently flagged by vendors.\n- Check browsers for ModHeader and similar flagged extensions and force-remove them via endpoint management tools.\n\n**Long-term improvements:**\n- Establish and enforce an allowlist policy for approved browser extensions across all managed endpoints using browser enterprise policies.\n- Implement a formal third-party software vetting process that includes periodic re-review of previously approved extensions and plugins.\n- Treat browser extensions as part of your software supply chain and require security assessments before organizational adoption.\n\n**Detection measures:**\n- Monitor endpoint network traffic for unexpected outbound connections from browser processes to unknown or newly registered domains.\n- Deploy endpoint detection tools capable of inspecting browser local storage for sensitive data written in plain text.\n- Subscribe to threat intelligence feeds and vendor security advisories to receive timely alerts when trusted tools are flagged or pulled.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 4 – Secure Configuration of Enterprise Assets and Software","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-161 – Supply Chain Risk Management","NIST SP 800-53 SI-7 – Software, Firmware, and Information Integrity","NIST SP 800-53 CM-7 – Least Functionality","NIST SP 800-53 AC-20 – Use of External Systems","GDPR Article 5(1)(f) – Integrity and Confidentiality","GDPR Article 25 – Data Protection by Design and by Default","ITIL Service Transition – Change and Configuration Management","published","2026-07-13T18:20:39.444924+00:00","2026-07-13T18:20:39.153+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fgoogle-and-microsoft-pull-modheader.html","google-and-microsoft-pull-modheader-with-1-6-million-installs-after-dormant-coll-995173","Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]