The Nano Defender and Nano Adblocker Supply Chain Attack
Updated 5 Oct 2026 · Incident date 15 Oct 2020 · browser extension
Nano Defender pre-15.0.0.206 -> 15.0.0.206 (and matching Nano Adblocker build)connect.jsIn October 2020, the Chrome versions of the browser extensions Nano Defender (build 15.0.0.206) and Nano Adblocker began running remote code after a change of owner. The original developer had sold the project in early October 2020.
The new owners added a file named connect.js that called code from remote servers and sent browser activity to them. Reports tie the extensions to unwanted activity on users' Instagram accounts.
What happened
A trusted ad blocker changed hands and the new owners shipped an update that acted against its users. Born City reports that the original developer, jspenguin2017, announced the sale in early October 2020 because he was unable to keep up the work. The buyers were developers in Turkey, according to the report in Lowyat and Born City. The new build, Nano Defender 15.0.0.206, added connect.js, which loaded code from remote servers. It sent user activity and browser data to https://def.dev-nano.com/.
Lowyat reports that the code liked large numbers of Instagram posts, reached accounts that were not open in the browser and uploaded authentication cookies. A user also reported unauthorized Instagram activity on their account. The uBlock Origin developer, Raymond Hill, inspected the code, as Lowyat and Born City report. Nano Adblocker was based on uBlock Origin code.
The users received the new version through normal automatic updates. Google removed the extensions from the Chrome Web Store.
Vigilance compares the version you trust with the new one. The new build gained a script that loads outside code, and Vigilance reports the file that gained that capability. See the scan block below.
Affected versions
- Nano Defender 15.0.0.206 and the matching Nano Adblocker build, in Chromium-based browsers such as Chrome and Edge when installed from the Chrome Web Store.
- Born City also lists User-Agent Switcher, Nano Contrib Filter - Placeholder Buster, Nano Defender Integration and the Nano filters extensions.
The sources disagree on other browsers. Lowyat states that the Firefox version and the Edge-store version were unaffected. The headline of the Ghacks report on this incident says to remove the extensions "except Firefox". Born City lists Firefox and Safari among affected browsers. Check each browser you use.
Indicators of compromise
- Script file:
connect.jsinside the extension. - Server:
def.dev-nano.com. - Extension version: Nano Defender 15.0.0.206.
- Unexpected likes or other activity on your Instagram account.
The sources give no extension IDs or file hashes, so this page lists none.
How to check
Open chrome://extensions and look for Nano Adblocker, Nano Defender and the related names. Check the version number of Nano Defender. You can also search the profile folder for the script name. On macOS:
grep -rl "dev-nano.com" ~/Library/Application\ Support/Google/Chrome/*/Extensions 2>/dev/null
A hit means that an installed extension contains the server name. Also check proxy and DNS logs for def.dev-nano.com.
What to do now
- Uninstall every Nano extension from each Chromium browser.
- Sign out of all websites. This ends sessions that a stolen cookie can use.
- Change your passwords, starting with social accounts such as Instagram.
- Review account activity for likes, posts or logins that you did not make.
- Use an ad blocker from a maintainer that you trust. Read the extension's owner and update history after a sale.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 60 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE connect.js It downloads from the internet and runs other programs.
Frequently asked questions
Is Nano Adblocker safe to use?
No. In October 2020, after a change of owner, the Chrome versions of Nano Adblocker and Nano Defender ran remote code and sent browser data. Google removed them from the Chrome Web Store.
Which version of Nano Defender was malicious?
Build 15.0.0.206 added the connect.js file that loaded remote code. A matching Nano Adblocker build was affected too.
Sources
More supply chain attacks
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- Trust Wallet browser extension v2.68 compromise 24 Dec 2025
- RedDirection campaign (Color Picker Geco and 17 others) 27 Jun 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.