ModHeader: Covert Data Exfiltration to api.stanfordstudies.com | Yunus Aydın Blog
ModHeader is a popular Chrome extension with over 1.6 million combined installs (900K Chrome + 700K Edge). This week, Reddit and HN lit up after people noticed it phones home to api.stanfordstudies.com/app/log. I pulled the latest version (v7.0.17) and did a full reverse engineering of the exfiltration pipeline. The results are worse than the initial reports suggested: AES-GCM encrypted IndexedDB storage, randomized upload timing, and evidence deletion after exfiltration.
Background
ModHeader is...
Read more at aydinnyunus.github.io