The Copyfish Chrome Extension Hijack

Updated 5 Oct 2026 · Incident date 29 Jul 2017 · browser extension

PackageCopyfish for Chrome 2.8.4 -> 2.8.5
Filecontent.js plus a remotely fetched ga.js

Copyfish for Chrome 2.8.5 is a hijacked update that injected ads into every page you visited. Attackers phished a developer account on 28 July 2017 and pushed the update on 29 July.

The extension had more than 37,500 users, according to The Hacker News. The Firefox version was not affected.

What happened

Attackers phished a Copyfish team member and used the access to publish a bad update, version 2.8.5, to the Chrome Web Store. BleepingComputer and The Hacker News describe the steps.

On 28 July 2017, a developer got an email that looked like it came from the Chrome Web Store team. It said the store will remove the extension unless the team updates it. The link led to a fake Google password page at chromedev.freshdesk.com. One team member entered a password. The attackers then moved the extension to their own developer account. The real owners lost the power to remove or fix it.

Version 2.8.5 went out on 29 July. It added JavaScript that loaded adverts into the pages that the user viewed. Chrome updates extensions with no user action, so most users got it. The hijack lasted about 24 hours before the public disclosure on 31 July, per BleepingComputer. The Unpkg CDN removed the malicious JavaScript files it hosted.

Proofpoint links the same method to a larger campaign. The attacker phished the developers of at least seven more extensions, including Web Developer, Chrometana, Infinity New Tab, Web Paint, Social Fixer, TouchVPN and Betternet VPN. In that campaign, the injected code swapped ads, sent users to fake repair alerts and stole Cloudflare credentials from logged-in users.

The update was a normal-looking version bump. The change was new script that fetches and runs remote code. Vigilance compares the version you trust with the new one and reports that kind of new power.

Affected versions

Only Copyfish for Chrome 2.8.5 is named as malicious.

The developers warned that they did not control the Chrome listing after the transfer. They said the attackers can push another update. Check the version that you have now, because a later version can be bad as well.

Indicators of compromise

Proofpoint lists these indicators in its report on the wider campaign. The report does not tie each one to Copyfish alone.

How to check

Open the Chrome extension list and read the Copyfish version and the owner. Then search your DNS or proxy logs for the domains above.

chrome://extensions
grep -Ei "partner-net.men|partnerwork.men|searchtab.win|redirect2.top" /var/log/dns/*.log

The log path is an example. Use the path of your own resolver or proxy.

What to do now

  1. Remove Copyfish from Chrome if it shows version 2.8.5. Use the trash icon on the extension card.
  2. Change the passwords for sites you used while 2.8.5 was active. Proofpoint reports that the wider campaign stole Cloudflare logins.
  3. Block the listed domains at the DNS layer.
  4. If you publish extensions, turn on two-step verification for the developer account. Do not enter your password from an email link.
  5. Review updates for extensions that gain new script or new permissions.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Chrome-2.8.4 --new Chrome-2.8.5
files scanned: 86

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    content.js
           It now downloads from the internet. It did not before.

Frequently asked questions

Which Copyfish version was hijacked?

Copyfish for Chrome 2.8.5, published on 29 July 2017 after attackers phished a team member on 28 July. The Firefox version was not affected.

What did the hijacked Copyfish extension do?

It added JavaScript that loaded adverts into the pages that users viewed. Proofpoint links the method to a wider campaign that also stole Cloudflare credentials.

How do I remove the hijacked Copyfish extension?

Open chrome://extensions, find Copyfish, and click the trash icon. Then change passwords for sites you used while the bad version was active.

Sources

  1. bleepingcomputer.com/news/security/copyfish-chrome-extension-hijacked-to-show-adware/
  2. proofpoint.com/us/threat-insight/post/threat-actor-goes-chrome-extension-hijacking-spree
  3. thehackernews.com/2017/07/chrome-extention-hacking-adware.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free