Proprietary · · 18 days

Copyfish Chrome extension shipped malware

Copyfish 2.8.5 was pushed through the Chrome Web Store after developer-account phishing in the 2017 extension hijacking spree.

Part of Chrome extension accounts shipped malware campaign

Copyfish was one of the legitimate Chrome extensions affected by the 2017 developer-account phishing spree. Attackers used stolen Chrome Web Store credentials to publish a malicious update through the official extension channel.

The affected release was Copyfish 2.8.5. The compromise was especially visible because the extension was already trusted by users for optical character recognition workflows, so the malicious update arrived as routine browser maintenance rather than as a new install decision.

The malicious extension activity sat inside the same Proofpoint-tracked campaign as Chrometana, Web Developer, Infinity New Tab, Web Paint, and Social Fixer. The common pattern was stolen publisher access followed by ad injection, traffic redirection, and credential-theft-capable JavaScript.

This leaf record preserves the Copyfish version and Chrome Web Store distribution boundary. The campaign record carries the shared phishing domains, redirect infrastructure, and cross-extension behavior.

Appendix · Affected releases

Copyfish chrome web store
2.8.5 sha256 7e91b8b0…f8734650 download unavailable
  • Recovered 2026-09-02: the malicious background script is held as a transcription of the code the extension's own author published after regaining the account. The payload it fetched is not held and appears unrecoverable.
  • The loader built an npm package name from the extension version, copyfish-npm-2-8-5, and pulled https://unpkg.com/copyfish-npm-2-8-5/<UTC hour>.js, so the payload rotated hourly across 24 files.
  • npm still holds that name as a security holding package and its time field lists the three removed versions 1.0.1501325940, 1.0.1501413946 and 1.0.1501416918, which as Unix timestamps are 29 and 30 July 2017.
  • The tarballs 404 on both npmjs.org and npmmirror.com, and the Internet Archive's only capture of the unpkg path is a 404 from 2019.

Indicators

  • domainclick.rdr11.top
  • domainchromedevelopment.site
  • domainlogin.chromeextensions.info
  • domainchromeextensions.info
  • domainwd7bdb20e4d622f6569f3e8503138c859d.win
  • domainsearchtab.win
  • domainredirect2.top
  • domainbrowser-updates.info
  • domainpartner-net.men
  • urlhttp://partner-net[.]men/code/pid/973820_BNX.js?rev=133

References

  1. Chrome extension developers under a barrage of phishing attacksbleepingcomputer.com
  2. Chrome extension developers under attackui.vision
  3. Threat actor goes on a Chrome extension hijacking spreeproofpoint.com
  4. Keeping our users safeblog.cloudflare.com
  5. Eight Chrome Extensions Hijacked to Deliver Malicious Code to 4.8 Million Usersbleepingcomputer.com

Source record: proprietary/copyfish-chrome-extension/meta.yaml