Chrome VPN Extension with 100k Installs Screenshots All Sites Users Visit
Key topics
A Chrome VPN extension with 100,000 installs was caught secretly screenshoting every site its users visited, sparking a heated debate about the validation process for browser extensions. Commenters pointed out that while the source code is technically available for inspection, it's often minified and obfuscated, making it nearly impossible for non-experts to detect malicious behavior. Some users called for reporting the extension to the Chrome store en masse, while others expressed skepticism about Google's willingness to take action, with one commenter cynically lumping it in with the "rest of the Google app store malware." The incident highlighted the importance of carefully reviewing browser extension permissions, as users often misunderstand the implications of granting certain permissions.
Snapshot generated from the HN discussion
Discussion Activity
Light discussionFirst comment
38m
Peak period
3
2-4h
Avg / period
1.8
Key moments
- 01Story posted
Aug 27, 2025 at 3:42 PM EDT
4 months ago
Step 01 - 02First comment
Aug 27, 2025 at 4:20 PM EDT
38m after posting
Step 02 - 03Peak activity
3 comments in 2-4h
Hottest window of the conversation
Step 03 - 04Latest activity
Aug 28, 2025 at 9:50 PM EDT
4 months ago
Step 04
Generating AI Summary...
Analyzing up to 500 comments to identify key contributors and discussion patterns
Want the full context?
Jump to the original sources
Read the primary article or dive into the live Hacker News thread when you're ready.
No, because they don't enforce their rules against obfuscation.
Even if there was it wouldn't help you - extensions regularly get sold to scammers who can push whatever update they want. I documented an extension with a few hundred thousand install base, that got sold and turned into malware. Overnight went from tens of lines of code un obfuscated to 10k+ lines obfuscated. Then they flooded the extensions review pages with fake reviews to burry complaints. I got a ticket open thru a contact which to Google's credit they investigated but they decided it wasn't violating enough policies to take any action.