ModHeader Extension Pulled for Dormant Data Theft Code
TechNadu · x · 2026-07-14
Browser extension ModHeader, which boasts roughly 1.6 million installations, has been removed from the official Google and Microsoft stores. Researchers discovered that its officially signed extension contains a complete, albeit dormant, data collection pipeline that could be activated at any time via standard updates. While there is currently no evidence of actual data theft, the necessary infrastructure is already in place.
Related event: Browser Extension ModHeader Pulled for Dormant Data Theft Code(2 posts)→
More from Safety
- Anthropic publishes its most detailed threat report, including an AI-designed drone swarm case — soumitrashukla9 · 2026-09-11
- OpenAI asks Congress whether an industry-wide AI slowdown would be legal — The Decoder · 2026-09-11
- Author retracts 'a16z partner calls for nationalising frontier AI' post: likely a troll — S_OhEigeartaigh · 2026-09-11
- Houthis tried to use Claude to design missile software, Anthropic says it blocked the attempts — Affectionate_Bee6434 · 2026-09-11
- AI safety community mocked as 'bridge engineers' who say bridges can never be safe — Dan_Jeffries1 · 2026-09-11
- Why So Many AI Researchers Think the Machines Could Kill Everyone — wiredmagazine · 2026-09-11