Malware basics: Analyzing a possible malware inside a Chrome extension


Today I came across a website with a sadly familiar problem. It had been attacked for malvertising. The curious thing is that the attacker has successfully hijacked the site so it redirects (sometimes) to a site that tries to “convince” you to install a Chrome extension that asks for permission to modify the content of all the sites that you visit. This is the analysis of the problem.

