Proprietary 2017-07-28 · 18 days ·Adware, Ad Fraud

Social Fixer Chrome extension shipped malware

Part of the Chrome extension accounts shipped malware campaign

Social Fixer 20.1.1 was pushed through the Chrome Web Store after developer-account phishing in the 2017 extension hijacking spree.

Story

Social Fixer was one of the legitimate Chrome extensions affected by the 2017 developer-account phishing spree. Attackers used stolen Chrome Web Store credentials to publish a malicious update through the official extension channel.

The affected release was Social Fixer 20.1.1. The extension already ran in the browser against social-network pages, so a malicious update could exploit permissions and user trust that had been granted long before the account takeover.

Proofpoint tied Social Fixer to the same extension-hijacking campaign as Copyfish, Web Developer, Chrometana, Infinity New Tab, and Web Paint. The shared pattern was stolen Chrome Web Store publisher access followed by ad injection, redirects, and credential-theft-capable script loading.

This leaf record preserves the Social Fixer version and store distribution boundary. The campaign record carries the shared phishing domains, redirect infrastructure, and cross-extension behavior.

Affected Artifacts

Social Fixer

chrome web store · Extension Package
Observed
2017-07-28 to 2017-08-15
Compromised Versions
  • 20.1.1
Fixed
Not listed

Incident Context

Motive
Financial Gain
Attribution
Group
Cause
Phishing
Transitive
No
Actor
Cybercriminal
User Impact
1500000

Indicators

  • domainclick.rdr11.top
  • domainchromedevelopment.site
  • domainlogin.chromeextensions.info
  • domainchromeextensions.info
  • domainwd7bdb20e4d622f6569f3e8503138c859d.win
  • domainsearchtab.win
  • domainredirect2.top
  • domainbrowser-updates.info
  • domainpartner-net.men
  • urlhttp://partner-net[.]men/code/pid/973820_BNX.js?rev=133

External References

Source record: proprietary/social-fixer-chrome-extension/meta.yaml