# Analysis of an advanced malicious Chrome extension

DevFeed: [Analysis of an advanced malicious Chrome extension](<https://devfeed.tech/articles/analysis-of-an-advanced-malicious-chrome-extension-36625.md>)

Original publisher: [Read original article](<https://palant.info/2025/02/03/analysis-of-an-advanced-malicious-chrome-extension/>)

Author: Wladimir Palant

Published: 2025-02-03T14:05:37Z

Content type: article

Language: en

Sources: [Almost Secure](<https://devfeed.tech/sources/almost-secure.md>)

Topics: [Chrome extension](<https://devfeed.tech/topics/chrome-extension.md>), [Extension](<https://devfeed.tech/topics/extension.md>), [Code](<https://devfeed.tech/topics/code.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [chrome](<https://devfeed.tech/tags/chrome.md>), [chrome-extension](<https://devfeed.tech/tags/chrome-extension.md>), [code](<https://devfeed.tech/tags/code.md>), [extension](<https://devfeed.tech/tags/extension.md>), [firebase](<https://devfeed.tech/tags/firebase.md>), [permission](<https://devfeed.tech/tags/permission.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [run](<https://devfeed.tech/tags/run.md>)

## AI overview

A technical analysis examines the Download Manager Integration Checklist Chrome extension and related extensions with malicious functionality. The article describes excessive website access requests, remotely downloaded content, dynamically added rules, and remote code execution through tabs.executeScript. It also reports that an update removed the malicious functionality and cleared extension storage.

## Source excerpt

Two weeks ago I published an article on 63 malicious Chrome extensions. In most cases I could only identify the extensions as malicious. With large parts of their logic being downloaded from some web servers, it wasn't possible to analyze their functionality in detail. However, for the Download Manager Integration Checklist extension I have all parts of the puzzle now. This article is a technical discussion of its functionality that somebody tried very hard to hide. I was also able to identify a number of related extensions that were missing from my previous article. Update (2025-02-04): An update to Download Manager Integration Checklist extension has been released a day before I published this article, clearly prompted by me asking adindex about this. The update removes the malicious functionality and clears extension storage. Luckily, I've saved both the previous version and its storage contents. Contents The problematic extensions "Remote configuration" functionality The code being executed The "session" handling Who is behind these extensions? The problematic extensions Since my previous article I found a bunch more extensions with malicious functionality that is almost identical to Download Manager Integration Checklist. The extension Auto Resolution Quality for YouTube™ does not seem to be malicious (yet?) but shares many remarkable oddities with the other extensions. Name Weekly active users Extension ID Featured Freemybrowser 10,000 bibmocmlcdhadgblaekimealfcnafgfn ✓ AutoHD for Twitch™ 195 didbenpmfaidkhohcliedfmgbepkakam Free simple Adult Blocker with password 1,000 fgfoepffhjiinifbddlalpiamnfkdnim Convert PDF to JPEG/PNG 20,000 fkbmahbmakfabmbbjepgldgodbphahgc Download Manager Integration Checklist 70,000 ghkcpcihdonjljjddkmjccibagkjohpi ✓ Auto Resolution Quality for YouTube™ 223 hdangknebhddccoocjodjkbgbbedeaam Adblock.mx - Adblock for Chrome 1,000 hmaeodbfmgikoddffcfoedogkkiifhfe ✓ Auto Quality for YouTube™ 100,000 iaddfgegjgjelgkanamleadckkpnjpjc Anti