The Web Developer for Chrome Hijack
Updated 5 Oct 2026 · Incident date 2 Aug 2017 · browser extension
Web Developer for Chrome 0.4.8 -> 0.4.9 (fixed in 0.5); same campaign also hit Chrometana 1.1.3, Infinity New Tab 3.12.3, Web Paint 1.2.1, Social Fixer 20.1.1, TouchVPN, Betternet VPNcontent.js and remotely fetched ga.jsWeb Developer for Chrome version 0.4.9 was a hijacked update that fetched remote JavaScript and injected ads into web pages. Version 0.5 fixed it.
The attacker phished the developer's Google account on 2 August 2017. Proofpoint links the same actor to a spree of hijacked Chrome extensions.
What happened
An attacker stole the developer's login with a fake Google email and then published a bad update through the official store. Chris Pederick, the developer, received an email that claimed to be from Google and said the extension needed an update for a new store policy. He entered his credentials on a fake page. He told The Register that the account had no two-factor authentication at that time.
The Hacker News reports that version 0.4.9 went out late on 2 August 2017. It fetched JavaScript from the web and ran it in the browser to inject ads. The extension had more than 1 million users (1,044,000 per The Hacker News). The Register reports that Pederick found the problem at about 6:30 AM the next day after user reports. He changed his password, unpublished the bad version and turned on two-factor authentication. Version 0.5 was out about two hours after discovery. The Firefox version was not affected.
Proofpoint describes a wider campaign. It says developer credentials were stolen with phishing emails that sent authors to fake login pages on domains such as chromedevelopment[.]site and login.chromeextensions[.]info. The bad code waited more than 10 minutes after install. It then fetched remote scripts using a domain generation algorithm, replaced ads, harvested Cloudflare credentials, and showed fake PC repair alerts. Proofpoint also says it exfiltrated Firebase and imagetwist credentials. Cloudflare removed the malicious domains after notification.
Read the Proofpoint report, The Hacker News and The Register.
The extension gained a new capability: it fetched and ran outside code on every page. For another case where a trusted owner or maintainer changed, see Add to Feedly.
Affected versions
Web Developer for Chrome 0.4.9 is the bad version, and 0.5 is the fix. Proofpoint lists these other hijacked extensions and versions.
- Web Developer 0.4.9 (fixed in 0.5)
- Chrometana 1.1.3
- Infinity New Tab 3.12.3 (compromised in May 2017)
- CopyFish 2.8.5
- Web Paint 1.2.1
- Social Fixer 20.1.1
- TouchVPN and Betternet VPN (suspected, late June 2017)
Indicators of compromise
- Fake login domains:
chromedevelopment[.]site,login.chromeextensions[.]info - Phishing server IP range:
31.186.103.146to31.186.103.149 - Script servers made by a domain generation algorithm, in the form
wd[hash][.]win - Ad injection domains:
partner-net[.]men,partnerwork[.]men - Exfiltration domains:
searchtab[.]win,redirect2[.]top - Files:
content.jsand a remotely fetchedga.jsscript.
How to check
List the version of each installed Chrome extension and look for the bad versions above. This command works on macOS. It prints the manifest version of every extension in the Default profile.
grep -H '"version"' ~/Library/Application\ Support/Google/Chrome/Default/Extensions/*/*/manifest.json
On Linux, use ~/.config/google-chrome/Default/Extensions instead. You can also open chrome://extensions and read the version. Search DNS logs for .win hosts that start with wd and for the domains above.
What to do now
- Update Web Developer to 0.5 or later. Remove any other extension on the list that you do not need.
- Change passwords for web accounts you used in the same browser, as The Hacker News advises.
- If you use Cloudflare, rotate your Cloudflare credentials and check the account for changes.
- If you publish extensions, turn on two-factor authentication on the developer account.
- Treat store-policy emails with care. Open the store dashboard directly, not the email link.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 73 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED content.js It now downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
Was the Web Developer Chrome extension hacked?
Yes. On 2 August 2017 an attacker used a phished developer login to publish version 0.4.9, which injected ads. Version 0.5 fixed it.
How many users did the Web Developer extension have?
The Hacker News reports 1,044,000 users. The Register reports more than 1 million.
Which other Chrome extensions were hijacked in the same campaign?
Proofpoint lists Chrometana, Infinity New Tab, CopyFish, Web Paint, Social Fixer, and suspected TouchVPN and Betternet VPN.
Sources
More supply chain attacks
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- Trust Wallet browser extension v2.68 compromise 24 Dec 2025
- RedDirection campaign (Color Picker Geco and 17 others) 27 Jun 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.