ModHeader Extension Pulled for Dormant Data Theft Code
TechNadu · x · 2026-07-14
Browser extension ModHeader, which boasts roughly 1.6 million installations, has been removed from the official Google and Microsoft stores. Researchers discovered that its officially signed extension contains a complete, albeit dormant, data collection pipeline that could be activated at any time via standard updates. While there is currently no evidence of actual data theft, the necessary infrastructure is already in place.
Related event: Browser Extension ModHeader Pulled for Dormant Data Theft Code(2 posts)→
More from Safety
- UK’s AISI may move into the Cabinet Office as an AI taskforce is planned — ShakeelHashim · 2026-07-21
- Minervini argues students should be guided, not micromanaged — PMinervini · 2026-07-21
- FBI warns scammers are impersonating IC3 with fake accounts and AI videos — TechNadu · 2026-07-21
- Researchers debate whether GPT-OSS ever had a clear harm case — aiamblichus · 2026-07-21
- Companies are still struggling to enforce audits and approvals for agentic systems — Electrical-Hall8869 · 2026-07-21
- Aidan Clark says the open-source debate has shifted from safety to sovereignty — _aidan_clark_ · 2026-07-21