Data Security Malicious ModHeader extension pulled from Chrome and Edge stores July 15, 2026 Share By SC Staff As outlined in Tech Radar, a popular browser extension named ModHeader, which had amassed over 1.6 million downloads across Chrome and Edge, has been identified as containing malicious spyware. The extension was found to be exfiltrating visited domain data to a server linked to Chinese actors. Security researchers at Stripe OLT discovered that version 7.0.18 of ModHeader included a hidden spyware SDK. This SDK was designed to collect visited domains, encrypt the data using AES-GCP, and transmit it daily to a server with Chinese ownership. While the data collection feature was inactive by default, the necessary code, encryption key, and upload schedule were embedded within the extension. The extension also functioned as adware, displaying ads and opening advertising tabs. The researchers attributed the attack to a Chinese-speaking threat actor with low confidence, with evidence including routing emails through Lark and Chinese strings within the code. Microsoft and Google have since removed ModHeader from their respective stores. However, users who had the extension installed prior to its removal remain at risk, and defenders are urged to identify and remove existing installations to prevent further data exfiltration. Source: Tech Radar SC Staff Related Data Security How to Build a Cloud, SaaS and AI Data Governance Program SC Media Editorial Intelligence, reviewed by Aparna Achanta July 14, 2026 Embed governance into the data movement process rather than applying governance after data has moved Data Security What Data Protection Actually Controls SC Media Editorial Intelligence, reviewed by Aparna Achanta July 14, 2026 Effective data protection determines whether stolen information is actually usable and how much business and regulatory damage an organization suffers after a breach Data Security Apple sues OpenAI over alleged theft of trade secrets by former employees SC Staff July 13, 2026 Apple alleges that former employee Chang Liu, who left the company to join OpenAI's hardware team, downloaded "dozens" of top-secret hardware files. Related Events Cybercast Beyond the Hype: The Cybersecurity Trends CISOs are Keeping an Eye on in 2026 On-Demand Event Cybercast Beyond the data perimeter: Why next-generation DSPM is the foundation for modern data security On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bit Block Cipher Cipher Ciphertext Cryptographic Hash Functions Cyclic Redundancy Check (CRC) Data Encryption Standard (DES) Diffie-Hellman Digital Signature Digital Signature Standard (DSS) You can skip this ad in 5 seconds