{
  "Event": {
    "analysis": "1",
    "date": "2026-07-14",
    "extends_uuid": "",
    "info": "[Threat Intel] ModHeader Malware: Inside the Chrome Spyware Google Removed",
    "protected": false,
    "publish_timestamp": "1784437676",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1784437676",
    "uuid": "1bcc382d-5298-455d-a2ac-98151b1eb94a",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Archive via Utility - T1560.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#bb2745",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Standard Encoding - T1132.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#ed66f6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"",
        "relationship_type": ""
      },
      {
        "colour": "#110e53",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DNS - T1071.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#3eb869",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Local Data Staging - T1074.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7da4ad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#47d9d3",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#56c932",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Symmetric Cryptography - T1573.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#c202a1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1566.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#029dd6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Software Extensions - T1176\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#82eae0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Domains - T1583.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9f8b1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"",
        "relationship_type": ""
      },
      {
        "colour": "#d596aa",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005e",
        "local": false,
        "name": "rectifyq:topic=\"supply-chain\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:operating-system=\"Linux\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:operating-system=\"Windows\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:operating-system=\"macOS\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:software-vendor=\"GoogleChrome\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784026806",
        "to_ids": false,
        "type": "link",
        "uuid": "db828e29-1813-4bd8-b36b-dd2fa29b8e7a",
        "value": "https://hackindex.io/research/modheader-malware-chrome-spyware",
        "Tag": [
          {
            "colour": "#6b003a",
            "local": true,
            "name": "workflow:todo=\"create-missing-misp-galaxy-cluster\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784026806",
        "to_ids": false,
        "type": "text",
        "uuid": "d8e11870-6043-41dd-8d55-587d5806a53b",
        "value": "ModHeader, a popular Chrome developer extension with over 800,000 users, was flagged and removed by Google for containing hidden spyware. Version 7.0.18 included a covert SDK disguised as a date library (dayjs) that harvested visited domain names, encrypted them using AES-GCM, and was configured to upload the data daily to api.stanfordstudies.com. Although the collection remained dormant due to an empty allowlist, the complete exfiltration infrastructure was present and operational. Additionally, the extension displayed active adware behavior, opening affiliate tabs on every update including on enterprise-managed machines. The malicious code shipped with official Chrome Web Store signatures, affecting both Chrome and Edge users. Forensic analysis revealed the extension locally stored 178MB of sensitive HTTP headers from all browsing activity, though no data was successfully exfiltrated from analyzed systems."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784026806",
        "to_ids": false,
        "type": "text",
        "uuid": "3aaeb3f5-78af-4861-abb4-beb45a1223d3",
        "value": "Name: ModHeader Malware: Inside the Chrome Spyware Google Removed\nAuthor: AlienVault\nAdversary: \nTags: [\"browser extension\", \"domain harvesting\", \"adware\", \"chrome web store\", \"modheader\", \"spyware\", \"supply chain attack\"]\nTgtd countries: []\nMlwr families: [\"ModHeader\"]\nAttack_ids: [\"T1560.001\", \"T1132.001\", \"T1539\", \"T1071.004\", \"T1074.001\", \"T1036.005\", \"T1204.002\", \"T1573.001\", \"T1566.002\", \"T1176\", \"T1005\", \"T1583.001\", \"T1041\", \"T1195.002\", \"T1071.001\", \"T1105\"]\nIndustries: []"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784435649",
        "to_ids": true,
        "type": "url",
        "uuid": "22b0f8ca-c8a5-4748-becf-a878299a6aee",
        "value": "https://modheader.com/api/ad-settings",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784435670",
        "to_ids": true,
        "type": "hostname",
        "uuid": "daea0d90-b7bd-4315-be0b-408bfdaa00fa",
        "value": "api.stanfordstudies.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784435691",
        "to_ids": true,
        "type": "hostname",
        "uuid": "73fb8aa3-cbc9-41a0-a740-fcb38b6d87f3",
        "value": "www.extensions-hub.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784435713",
        "to_ids": true,
        "type": "url",
        "uuid": "d2c0b411-34e1-4de3-b647-a9086a4d239e",
        "value": "modheader.com/api/ad-settings",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784429576",
        "to_ids": true,
        "type": "chrome-extension-id",
        "uuid": "2558c417-9647-4d7c-a3a0-3c50ae912a37",
        "value": "idgpnmonknjnojddfkpgkljpfnnfcklj"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784429576",
        "to_ids": true,
        "type": "chrome-extension-id",
        "uuid": "c9d261c7-b09d-4792-aa06-e606d15cd10a",
        "value": "opgbiafapkbbnbnjcdomjaghbckfkglc"
      }
    ]
  }
}