Malicious ModHeader Extension with 1.6M Installs Exfiltrated Browsing Data to Chinese Server

A trusted browser extension used by developers was found secretly stealing visited domains and sending encrypted data daily to a server linked to Chinese actors. Despite removal from official stores, existing installations remain a security risk.

Malicious ModHeader Extension with 1.6M Installs Exfiltrated Browsing Data to Chinese Server
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What happened with the ModHeader browser extension?

ModHeader, a popular browser extension for Chrome and Edge with over 1.6 million downloads, was discovered embedding spyware functions in one of its updates (version 7.0.18). This spyware secretly collected information about websites visited by users, encrypted this data, and then sent it daily to a remote server controlled by an actor believed to be Chinese. Alongside data exfiltration, the extension also displayed unauthorized advertisements, behaving like adware even on managed enterprise devices.

Why does this matter to users and organizations?

❗️❗️A widely used browser extension, ModHeader, has been removed from the  Chrome Web Store after researchers found that its signed release contained  a dormant capability to collect, encrypt, and potentially upload users'
❗️❗️A widely used browser extension, ModHeader, has been removed from the Chrome Web Store after researchers found that its signed release contained a dormant capability to collect, encrypt, and potentially upload users'

Many developers and security professionals use ModHeader to modify HTTP headers for testing and troubleshooting. The extension's compromised version essentially violated users' privacy and security by harvesting sensitive browsing data without consent. Since the extension was installed widely—approximately 900,000 users on Chrome and 700,000 on Edge—many devices remain vulnerable if the extension has not been uninstalled, exposing potentially sensitive browsing habits to malicious actors.

Risks involved

  • Data Privacy Violation: The stolen visited domains could reveal confidential or sensitive browsing activities.
  • Persistent Threat: Removal from Chrome and Edge stores does not remove the extension from devices where it is already installed.
  • Enterprise Impact: Even enterprise-managed devices were affected, increasing organizational exposure.

How is the spyware operating technically?

The spyware built into ModHeader encrypts collected domain data using AES-GCP encryption before sending it once per day to an external server. The exfiltration mechanism is one-way: while the server receives data, no reported command-and-control (C2) functionality allows this server to send commands back to the extension. This limits active control by the attacker but still results in information leakage.

Who is behind the attack?

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant  Collector Found
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

Security researchers attribute the attack, with low confidence, to a Chinese-speaking threat group based on several indicators: use of Chinese-language code strings, a Simplified Chinese locale in the extension, and data routing through infrastructure commonly used by Chinese teams. However, this attribution is not definitive and should be treated cautiously.

What can affected users and organizations do?

  1. Immediately uninstall ModHeader version 7.0.18 and any subsequent suspicious versions.
  2. Audit endpoints for remaining installations of the compromised extension, especially within organizational environments.
  3. Review browser security policies and consider applying stricter extension whitelisting.
  4. Monitor network traffic for unusual encrypted uploads corresponding to the exfiltration pattern.
  5. Keep browsers and extensions updated from trusted sources, avoiding unofficial builds.

How did Google and Microsoft respond?

ModHeader Chrome Extension Exposes 900,000 Users to Potential Browsing  History Theft
ModHeader Chrome Extension Exposes 900,000 Users to Potential Browsing History Theft

Following security disclosures, Microsoft removed ModHeader from its Edge repository on June 3, 2026, and Google pulled it from the Chrome Web Store on July 10, 2026. These removals prevent further downloads but do not automatically eliminate risks from already infected devices.

Key takeaway for cyber security professionals and users

This incident highlights that even trusted development tools can be compromised to carry hidden spyware and adware functions. Simply deleting an extension from stores is insufficient; active endpoint remediation is vital to remove malicious code. Continuous vigilance over browser extensions, thorough auditing, and strict extension management policies are critical defenses. Users and organizations must verify the integrity of their tools regularly to prevent silent data leaks that could expose sensitive online activities.

React to this story

Related Posts