{"id":2338,"date":"2018-09-07T09:51:10","date_gmt":"2018-09-07T09:51:10","guid":{"rendered":"https:\/\/www.varutra.com\/blog\/?p=1534"},"modified":"2023-03-24T10:27:36","modified_gmt":"2023-03-24T04:57:36","slug":"security-advisory-mega-chrome-extension-hijack","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/","title":{"rendered":"Security Advisory- MEGA Chrome Extension Hijack"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2018\/09\/mega-blog-1024x582.png\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"mega blog - Varutra Consulting\"><\/p>\n<h3 style=\"text-align: left\"><strong>What is MEGA?<\/strong><\/h3>\n<p style=\"text-align: left\">MEGA is a cloud storage and file hosting service offered by Mega Limited, a New Zealand-based company. The service is offered primarily through web-based apps. Mega mobile apps are also available for Windows Phone, Android and iOS.<\/p>\n<p style=\"text-align: left\">Mega is known for its security feature where all files are end-to-end encrypted locally before they are uploaded. This prevents anyone from accessing the files without knowledge of the pass key used for encryption. As of January 20, 2018, Mega has 100 million registered users in more than 245 countries and territories, and more than 40 billion files have been uploaded to the service.<\/p>\n<p><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/yyyyyyyyyy.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1535\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/yyyyyyyyyy.png\" alt=\"MEGA Chrome Extension\" width=\"489\" height=\"315\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Affected Version<\/strong><\/h3>\n<p>MEGA Chrome Extension 3.39.4<\/p>\n<p>The Firefox version of MEGA has not been impacted or tampered with, and users accessing MEGA through its official website (https:\/\/mega.nz) without the Chrome extension are also not affected by the breach.<\/p>\n<p>All extracted information will be immediately reported to a hacker-controlled server located in Ukraine. A list of the target services includes the following:<\/p>\n<ul>\n<li>Google<\/li>\n<li>Amazon<\/li>\n<li>Microsoft<\/li>\n<li>GitHub<\/li>\n<li>com<\/li>\n<li>Google Webstore Login<\/li>\n<li>My Ether Wallet<\/li>\n<li>My Monero<\/li>\n<li>IDEX Market<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1536\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra1.png\" alt=\"MEGA extension window in browser\" width=\"483\" height=\"322\" \/><\/a><\/p>\n<p style=\"text-align: center\"><em>Fig: MEGA extension window in browser<\/em><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Current Scenario<\/strong><\/h3>\n<p>On 4 September at 14:30 UTC, an unknown attacker managed to hack into MEGA&#8217;s Google Chrome web store account and uploaded a malicious version 3.39.4 to the web store. When installed the extension will monitor for specific login form submissions to Amazon, Microsoft, GitHub, and Google.<\/p>\n<p>The hijacked MEGA extension then sent all the stolen information back to an attacker&#8217;s server located in Ukraine, which is then used by the attackers to log in to the victims accounts, and also extract the crypto currency private keys to steal user digital currencies.<\/p>\n<p>Although the company has not revealed the number of users affected by the security incident, it is believed that the malicious version of the MEGA Chrome extension may have been installed by tens of millions of users.<a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra2.png.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1537\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra2.png.jpg\" alt=\"Blog post published by the company about Hijack\" width=\"438\" height=\"255\" \/><\/a><\/p>\n<p style=\"text-align: center\"><em>Fig: Blog post published by the company<\/em><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>How this attack works?<\/strong><\/h3>\n<p>It would perform monitoring of any form submission where the URL contains the strings Register or Login or variables exist that are named &#8220;username&#8221;, &#8220;email&#8221;, &#8220;user&#8221;, &#8220;login&#8221;, &#8220;usr&#8221;, &#8220;pass&#8221;, &#8220;passwd&#8221;, or &#8220;password&#8221;. If the extension detected any of these form submissions or data variables, it would send the credentials and variables values to a host in Ukraine called https:\/\/www.megaopac.host\/.<\/p>\n<p>To make matters worse this extension will also monitor for the following URL patterns: &#8220;https:\/\/www.myetherwallet.com\/*&#8221;, &#8220;https:\/\/mymonero.com\/*&#8221;, &#8220;https:\/\/idex.market\/*&#8221;, and if detected, would execute Javascript that would attempt to steal the crypto currency private keys for the logged in user from these sites.<\/p>\n<p><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra3.png.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1538 size-large\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra3.png-1024x584.jpg\" alt=\"Monitoring login attempts to various sites\" width=\"540\" height=\"308\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/varutra3.png-1024x584.jpg 1024w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/varutra3.png-300x171.jpg 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/varutra3.png-768x438.jpg 768w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/varutra3.png.jpg 1316w\" sizes=\"(max-width: 540px) 100vw, 540px\" \/><\/a><\/p>\n<p style=\"text-align: center\"><em>Fig: Monitoring login attempts to various sites<\/em><\/p>\n<p style=\"text-align: center\"><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra4.png.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1539\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra4.png.jpg\" alt=\"Stealing variables with certain names\" width=\"535\" height=\"292\" \/><\/a><\/p>\n<p style=\"text-align: center\"><em>Fig: Stealing variables with certain names<\/em><\/p>\n<p style=\"text-align: center\"><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra5.png.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1540\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra5.png.jpg\" alt=\"Sending information to attackers\" width=\"545\" height=\"169\" \/><\/a><\/p>\n<p style=\"text-align: center\"><em>Fig: Sending information to attackers<\/em><\/p>\n<p style=\"text-align: center\"><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra6.png.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1541 size-large\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra6.png-1024x522.jpg\" alt=\"Capturing crypto currency keys\" width=\"540\" height=\"275\" \/><\/a><\/p>\n<p style=\"text-align: center\"><em>Fig: Capturing crypto currency keys<\/em><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Prevention attempts by officials<\/strong><\/h3>\n<p>The main reason for this attack was Google\u2019s decision to disallow publisher signatures on Chrome extensions and relying solely on signing them automatically after upload to the Chrome web store, which removes an important barrier to external compromise. As a prevention attempt Google removed the MEGA extension from its Chrome Web Store five hours after the breach.<\/p>\n<p>However, after four hours of the security breach MEGA updated the extension with a clean MEGA version (3.39.5), auto-updating all the affected installations.<\/p>\n<p><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1542\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/varutra7.png\" alt=\"Error\" width=\"548\" height=\"186\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Recommendations<\/strong><\/h3>\n<ol>\n<li>Users who had installed the extension should uninstall the MEGA version 3.39.4.<\/li>\n<li>Change your passwords at any accounts, especially financial, shopping, banking, and government institutions, that you may have used.<\/li>\n<li>Consider resetting the Chrome browser to make sure the extension is completely removed. (Settings-&gt;Show advanced settings-&gt;Restore settings to their original defaults)<\/li>\n<li>Until more information is available about the cause of the incident, it is recommended that all users should stop the use of the MEGA Chrome extension.<\/li>\n<li>Transfer any cryptocurrency funds, including tokens, to another address.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h3><strong>Some best practices to stay safe in future<\/strong><\/h3>\n<ol>\n<li>The incident highlights a security danger with third-party Chrome extensions. If you have any unused extension installed on your Chrome browser, it&#8217;s a good idea to remove them.<\/li>\n<li>Do not install potentially unwanted extensions on browser.<\/li>\n<li>Before granting permission, verify the reason why an application requires elevated permissions like \u2018Read and Change your data on websites you visit&#8217;.<\/li>\n<li>Use two-factor authentication for any resources that support financial information, because in such cases, even if criminals get to your credentials, they won\u2019t be able to compromise your accounts.<\/li>\n<li>Password managers are particularly helpful when need to change a whole lot of passwords at the same time.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h3><strong>References<\/strong><\/h3>\n<ol>\n<li><a href=\"https:\/\/mega.nz\/start%20\">https:\/\/mega.nz\/start<\/a><\/li>\n<li><a href=\"https:\/\/www.neowin.net\/news\/megas-chrome-extension-suffers-breach-steals-user-credentials-and-crypto-keys\">https:\/\/www.neowin.net\/news\/megas-chrome-extension-suffers-breach-steals-user-credentials-and-crypto-keys<\/a><\/li>\n<li><a href=\"https:\/\/sensorstechforum.com\/mega-chrome-extension-hacked-user-passwords-stolen-uninstall-asap\/\">https:\/\/sensorstechforum.com\/mega-chrome-extension-hacked-user-passwords-stolen-uninstall-asap\/<\/a><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>Author,<\/p>\n<div><strong>Jinto T.K.<\/strong><\/div>\n<div>SOC Team<\/div>\n<div><em>Varutra Consulting Pvt. Ltd<\/em><\/div>","protected":false},"excerpt":{"rendered":"<p>What is MEGA? MEGA is a cloud storage and file hosting service offered by Mega Limited, a New Zealand-based company. The service is offered primarily&#8230;<\/p>\n","protected":false},"author":3,"featured_media":3383,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[270,277,266,273,274],"tags":[131,132,133,134,136,137,138,127],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.7.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"The MEGA Chrome Extension Hijack, and users accessing MEGA through its official website without the Chrome extension are also not affected by the breach.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"kalpadmin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.7.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"MEGA Chrome Extension Hijack - Security Advisory\" \/>\n\t\t<meta property=\"og:description\" content=\"The MEGA Chrome Extension Hijack, and users accessing MEGA through its official website without the Chrome extension are also not affected by the breach.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/mega-blog.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/mega-blog.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t\t<meta property=\"og:image:height\" content=\"728\" \/>\n\t\t<meta property=\"article:section\" content=\"Data Leakage\" \/>\n\t\t<meta property=\"article:tag\" content=\"chrome extension\" \/>\n\t\t<meta property=\"article:tag\" content=\"chrome hijack\" \/>\n\t\t<meta property=\"article:tag\" content=\"extension\" \/>\n\t\t<meta property=\"article:tag\" content=\"google chrome\" \/>\n\t\t<meta property=\"article:tag\" content=\"hijack\" \/>\n\t\t<meta property=\"article:tag\" content=\"mega\" \/>\n\t\t<meta property=\"article:tag\" content=\"mega hijack\" \/>\n\t\t<meta property=\"article:tag\" content=\"security advisory\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2018-09-07T09:51:10+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-03-24T04:57:36+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"MEGA Chrome Extension Hijack - Security Advisory\" \/>\n\t\t<meta name=\"twitter:description\" content=\"The MEGA Chrome Extension Hijack, and users accessing MEGA through its official website without the Chrome extension are also not affected by the breach.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/mega-blog.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpadmin\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#article\",\"name\":\"MEGA Chrome Extension Hijack - Security Advisory\",\"headline\":\"Security Advisory- MEGA Chrome Extension Hijack\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2018\\\/09\\\/mega-blog.png\",\"width\":1280,\"height\":728,\"caption\":\"mega blog\"},\"datePublished\":\"2018-09-07T09:51:10+05:30\",\"dateModified\":\"2023-03-24T10:27:36+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#webpage\"},\"articleSection\":\"Data Leakage, Data Privacy, Security Advisory, Security Best Practices, Security Hardening, Chrome Extension, Chrome Hijack, Extension, Google Chrome, Hijack, MEGA, MEGA Hijack, Security Advisory\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/security-advisory\\\/#listItem\",\"name\":\"Security Advisory\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/security-advisory\\\/#listItem\",\"position\":2,\"name\":\"Security Advisory\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/security-advisory\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#listItem\",\"name\":\"Security Advisory- MEGA Chrome Extension Hijack\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#listItem\",\"position\":3,\"name\":\"Security Advisory- MEGA Chrome Extension Hijack\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/security-advisory\\\/#listItem\",\"name\":\"Security Advisory\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/\",\"name\":\"kalpadmin\",\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/\",\"name\":\"MEGA Chrome Extension Hijack - Security Advisory\",\"description\":\"The MEGA Chrome Extension Hijack, and users accessing MEGA through its official website without the Chrome extension are also not affected by the breach.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2018\\\/09\\\/mega-blog.png\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#mainImage\",\"width\":1280,\"height\":728,\"caption\":\"mega blog\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-mega-chrome-extension-hijack\\\/#mainImage\"},\"datePublished\":\"2018-09-07T09:51:10+05:30\",\"dateModified\":\"2023-03-24T10:27:36+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>MEGA Chrome Extension Hijack - Security Advisory<\/title>\n\n","aioseo_head_json":{"title":"MEGA Chrome Extension Hijack - Security Advisory","description":"The MEGA Chrome Extension Hijack, and users accessing MEGA through its official website without the Chrome extension are also not affected by the breach.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#article","name":"MEGA Chrome Extension Hijack - Security Advisory","headline":"Security Advisory- MEGA Chrome Extension Hijack","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/mega-blog.png","width":1280,"height":728,"caption":"mega blog"},"datePublished":"2018-09-07T09:51:10+05:30","dateModified":"2023-03-24T10:27:36+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#webpage"},"articleSection":"Data Leakage, Data Privacy, Security Advisory, Security Best Practices, Security Hardening, Chrome Extension, Chrome Hijack, Extension, Google Chrome, Hijack, MEGA, MEGA Hijack, Security Advisory"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/#listItem","name":"Security Advisory"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/#listItem","position":2,"name":"Security Advisory","item":"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#listItem","name":"Security Advisory- MEGA Chrome Extension Hijack"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#listItem","position":3,"name":"Security Advisory- MEGA Chrome Extension Hijack","previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/#listItem","name":"Security Advisory"}}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","description":"Secure your digital world with our Cybersecurity services.","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/","name":"kalpadmin","image":{"@type":"ImageObject","url":"https:\/\/secure.gravatar.com\/avatar\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/","name":"MEGA Chrome Extension Hijack - Security Advisory","description":"The MEGA Chrome Extension Hijack, and users accessing MEGA through its official website without the Chrome extension are also not affected by the breach.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2018\/09\/mega-blog.png","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#mainImage","width":1280,"height":728,"caption":"mega blog"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/#mainImage"},"datePublished":"2018-09-07T09:51:10+05:30","dateModified":"2023-03-24T10:27:36+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"MEGA Chrome Extension Hijack - Security Advisory","og:description":"The MEGA Chrome Extension Hijack, and users accessing MEGA through its official website without the Chrome extension are also not affected by the breach.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/mega-blog.png","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/mega-blog.png","og:image:width":"1280","og:image:height":"728","article:section":"Data Leakage","article:tag":["chrome extension","chrome hijack","extension","google chrome","hijack","mega","mega hijack","security advisory"],"article:published_time":"2018-09-07T09:51:10+00:00","article:modified_time":"2023-03-24T04:57:36+00:00","twitter:card":"summary_large_image","twitter:title":"MEGA Chrome Extension Hijack - Security Advisory","twitter:description":"The MEGA Chrome Extension Hijack, and users accessing MEGA through its official website without the Chrome extension are also not affected by the breach.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/mega-blog.png","twitter:label1":"Written by","twitter:data1":"kalpadmin","twitter:label2":"Est. reading time","twitter:data2":"4 minutes"},"aioseo_meta_data":{"post_id":"2338","title":"MEGA Chrome Extension Hijack&nbsp;- Security Advisory","description":"The MEGA Chrome Extension Hijack, and users accessing MEGA through its official website without the Chrome extension are also not affected by the breach.","keywords":[],"keyphrases":{"focus":{"keyphrase":"MEGA","score":90,"analysis":{"keyphraseInTitle":{"score":9,"maxScore":9,"error":0},"keyphraseInDescription":{"score":9,"maxScore":9,"error":0},"keyphraseLength":{"score":9,"maxScore":9,"error":0,"length":1},"keyphraseInURL":{"score":5,"maxScore":5,"error":0},"keyphraseInIntroduction":{"score":9,"maxScore":9,"error":0},"keyphraseInSubHeadings":{"score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"score":9,"maxScore":9,"error":0}}},"additional":[{"keyphrase":"MEGA Chrome Extension ","score":83,"analysis":{"keyphraseInDescription":{"score":9,"maxScore":9,"error":0},"keyphraseLength":{"score":9,"maxScore":9,"error":0,"length":3},"keyphraseInIntroduction":{"score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"score":9,"maxScore":9,"error":0}}},{"keyphrase":"MEGA Chrome Extension Hijack","score":67,"analysis":{"keyphraseInDescription":{"score":9,"maxScore":9,"error":0},"keyphraseLength":{"score":9,"maxScore":9,"error":0,"length":4},"keyphraseInIntroduction":{"score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"score":3,"maxScore":9,"error":1}}},{"keyphrase":"Hijack","score":83,"analysis":{"keyphraseInDescription":{"score":9,"maxScore":9,"error":0},"keyphraseLength":{"score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"score":9,"maxScore":9,"error":0}}}]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2018\/09\/mega-blog.png","og_image_width":"1280","og_image_height":"728","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Data Leakage","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":null,"created":"2021-10-27 15:16:26","updated":"2026-05-24 09:18:18","ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-05-22 14:15:05"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/\" title=\"Security Advisory\">Security Advisory<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tSecurity Advisory- MEGA Chrome Extension Hijack\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Security Advisory","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/"},{"label":"Security Advisory- MEGA Chrome Extension Hijack","link":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-mega-chrome-extension-hijack\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/2338"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=2338"}],"version-history":[{"count":6,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/2338\/revisions"}],"predecessor-version":[{"id":21194,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/2338\/revisions\/21194"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/3383"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=2338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=2338"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=2338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}