The Nano Defender and Nano Adblocker Supply Chain Attack

Updated 5 Oct 2026 · Incident date 15 Oct 2020 · browser extension

PackageNano Defender pre-15.0.0.206 -> 15.0.0.206 (and matching Nano Adblocker build)
Fileconnect.js

In October 2020, the Chrome versions of the browser extensions Nano Defender (build 15.0.0.206) and Nano Adblocker began running remote code after a change of owner. The original developer had sold the project in early October 2020.

The new owners added a file named connect.js that called code from remote servers and sent browser activity to them. Reports tie the extensions to unwanted activity on users' Instagram accounts.

What happened

A trusted ad blocker changed hands and the new owners shipped an update that acted against its users. Born City reports that the original developer, jspenguin2017, announced the sale in early October 2020 because he was unable to keep up the work. The buyers were developers in Turkey, according to the report in Lowyat and Born City. The new build, Nano Defender 15.0.0.206, added connect.js, which loaded code from remote servers. It sent user activity and browser data to https://def.dev-nano.com/.

Lowyat reports that the code liked large numbers of Instagram posts, reached accounts that were not open in the browser and uploaded authentication cookies. A user also reported unauthorized Instagram activity on their account. The uBlock Origin developer, Raymond Hill, inspected the code, as Lowyat and Born City report. Nano Adblocker was based on uBlock Origin code.

The users received the new version through normal automatic updates. Google removed the extensions from the Chrome Web Store.

Vigilance compares the version you trust with the new one. The new build gained a script that loads outside code, and Vigilance reports the file that gained that capability. See the scan block below.

Affected versions

The sources disagree on other browsers. Lowyat states that the Firefox version and the Edge-store version were unaffected. The headline of the Ghacks report on this incident says to remove the extensions "except Firefox". Born City lists Firefox and Safari among affected browsers. Check each browser you use.

Indicators of compromise

The sources give no extension IDs or file hashes, so this page lists none.

How to check

Open chrome://extensions and look for Nano Adblocker, Nano Defender and the related names. Check the version number of Nano Defender. You can also search the profile folder for the script name. On macOS:

grep -rl "dev-nano.com" ~/Library/Application\ Support/Google/Chrome/*/Extensions 2>/dev/null

A hit means that an installed extension contains the server name. Also check proxy and DNS logs for def.dev-nano.com.

What to do now

  1. Uninstall every Nano extension from each Chromium browser.
  2. Sign out of all websites. This ends sessions that a stolen cookie can use.
  3. Change your passwords, starting with social accounts such as Instagram.
  4. Review account activity for likes, posts or logins that you did not make.
  5. Use an ad blocker from a maintainer that you trust. Read the extension's owner and update history after a sale.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Nano-prev --new Nano-current
files scanned: 60 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   connect.js
           It downloads from the internet and runs other programs.

Frequently asked questions

Is Nano Adblocker safe to use?

No. In October 2020, after a change of owner, the Chrome versions of Nano Adblocker and Nano Defender ran remote code and sent browser data. Google removed them from the Chrome Web Store.

Which version of Nano Defender was malicious?

Build 15.0.0.206 added the connect.js file that loaded remote code. A matching Nano Adblocker build was affected too.

Sources

  1. borncity.com/win/2020/10/22/datenklau-browser-extension-nano-adblocker-defender-co-entfernen/
  2. lowyat.net/2020/224264/chromium-versions-nano-adblocker-malware/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free