The Bottom Line: The popular HTTP header extension ModHeader contained code to capture browser history that could have been activated through a simple update without additional permissions.
Google and Microsoft removed the browser extension ModHeader with 1.6 million downloads from their stores after British security firm Stripe OLT discovered hidden, previously inactive data-harvesting code.
Google Chrome and Microsoft Edge removed the ModHeader extension on July 10 and July 3, 2026 respectively from their app stores. The tool had approximately 900,000 installations in Chrome and 700,000 in Edge. Security analysts at British firm Stripe OLT identified in official version 7.0.18 a hidden code block designed to capture and transmit browser activity. Previous analyses suggest that no active data collection or transmission took place.
The infrastructure of the inactive code operates according to the following principle: After installation, the extension generates a digital device fingerprint. During use, it captures the domains of up to 1000 visited websites, encrypts them using AES-256-GCM, and stores them locally. A scheduled task was intended to transmit the data daily to “api.stanfordstudies.com”. This process remained ineffective because a necessary allowlist was empty in the shipped version. However, an operator could have activated this functionality via routine update without requesting additional permissions. Independent analyses of versions 7.0.17 and 7.0.18 confirmed this architecture.
Beyond the collection code, other background functions were running. On installation, update, and uninstallation, ModHeader sent telemetry data to “extensions-hub.com”. Another script logged HTTP metadata unencrypted in local storage. The domains intended for data transmission do not correspond to actual educational institutions; according to analysts, the server infrastructure suggests a common operator. Automated scanners previously assessed the extension as low-risk because the spyware code was obfuscated and data transmission in sandbox environments was not triggered by the empty allowlist.
For CISOs and system administrators, the following measures are recommended: Corporate networks should be scanned for the presence of ModHeader and the extension removed from endpoints. Since ModHeader in earlier versions also stored complete HTTP headers locally, any credentials used therein such as API keys, bearer tokens, and session cookies must be considered compromised and renewed. In the network, communication to “stanfordstudies.com” and “extensions-hub.com” should be blocked at the proxy and DNS level, and logs should be searched for the extension ID.
Source: www.it-daily.net · Published July 19, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.