ModHeader Extension Pulled for Dormant Data Theft Code

TechNadu · x · 2026-07-14

Browser extension ModHeader, which boasts roughly 1.6 million installations, has been removed from the official Google and Microsoft stores. Researchers discovered that its officially signed extension contains a complete, albeit dormant, data collection pipeline that could be activated at any time via standard updates. While there is currently no evidence of actual data theft, the necessary infrastructure is already in place.

Related event: Browser Extension ModHeader Pulled for Dormant Data Theft Code(2 posts)→

Original post →

More from Safety

Safety channel →