• Skip to main content
  • Skip to primary sidebar
  • Deals
  • Features
  • Guides
  • Chromebooks
  • Videos
  • Podcast
  • More +
    • Reviews
    • Unboxing
    • Upcoming Devices
    • Chromebook Plus
    • Chrome
    • ChromeOS
    • Chrome OS Flex
  • Search
  • Sign Up
  • Log In
Chrome Unboxed – The Latest Chrome OS News

Chrome Unboxed - The Latest Chrome OS News

A Space for All Things Chrome, Google, and More!

  • Deals
  • Features
  • Guides
  • Chromebooks
  • Videos
  • Podcast
  • More +
    • Reviews
    • Unboxing
    • Upcoming Devices
    • Chromebook Plus
    • Chrome
    • ChromeOS
    • Chrome OS Flex
  • Search
  • Sign Up
  • Log In

Mega Chrome Extension Compromised: Usernames, Passwords and Even Monero At Risk

September 7, 2018 By Gabriel Brangers View Comments

Another Chrome Extension has come under attack this week. Mega Cloud Storage service based in New Zealand announced Tuesday in a blog post that their Chrome Web Store account had been compromised and the attacker was able to upload a corrupted version of the Mega Chrome extension.

Unfortunately, Chrome extensions generally update automatically in the background and for roughly four hours, the malicious extension was live in the Web Store.

Xremove ads

Upon installation or auto update, it would ask for elevated permissions (Read and change all your data on the websites you visit) that MEGA’s real extension does not require and would (if permissions were granted) exfiltrate credentials for sites including amazon.com, live.com, github.com, google.com (for webstore login), myetherwallet.com, mymonero.com, idex.market and HTTP POST requests to other sites, to a server located in Ukraine. Note that mega.nz credentials were not being exfiltrated.

The alarms began to sound when a Redditor took to the web to warn the crypto community that passwords and encrypted keys for a number of Cryptocurrency wallets as well as the Ethereum exchange IDEX.

PSA: The official MEGA extension has been compromised and now includes functionality to steal your Monero: https://t.co/vzWwcM9E5k

— Monero || #xmr (@monero) September 4, 2018

Featured Videos

Xremove ads

If you aren’t familiar with Mega, they were rebirthed from the failed Hong Kong-based Megaupload file storage service. After being shut down in 2012 for piracy, the companies founder launched Mega as a cloud storage and file sharing platform with the motto “The Privacy Company.” This breach is a low blow to the company that is reported to have 100 million-plus users around the globe.

Mega was quick to make the attack public once it was identified and quickly uploaded a clean version of the extension to the Chrome Web Store. The company also pointed out that other Mega products including the Firefox extension were unaffected and that the vulnerability of the Chrome extension was due the manner in which the package file signatures are assigned

MEGA uses strict release procedures with multi-party code review, robust build workflow and cryptographic signatures where possible. Unfortunately, Google decided to disallow publisher signatures on Chrome extensions and is now relying solely on signing them automatically after upload to the Chrome webstore, which removes an important barrier to external compromise.

This is just another in a long line of security holes in the Chrome Web Store over the past few years. Google has recently given the Store a facelift and it is our hope and even plea that as it continues to evolve, the folks at Mountain View will give the protocol for publishing Chrome apps and extensions will be given a revamp.

Xremove ads

If you are a Mega user, your extension should have updated automatically to the secure, clean version. To be safe, head to chrome://extensions and ensure you have version 3.39.5 of the Mega extension or you can download it from the Chrome Web Store here.

Check Out Chrome Unboxed’s Top Picks On Amazon

Filed Under: Apps, Chrome, News

About Gabriel Brangers

Lover of all things coffee. Foodie for life. Passionate drummer, hobby guitar player, Web designer and proud Army Veteran. I have come to drink coffee and tell the world of all things Chrome. "Whatever you do, Carpe the heck out of that Diem" - Roman poet, Horace. Slightly paraphrased.

Primary Sidebar

Xremove ads

Deals

The best Chromebook deals today

By Robby Payne
December 29, 2025

The Acer Chromebook Plus Spin 514 hits an all-time low price of $499

By Robby Payne
December 23, 2025

Save $220 on the powerful, versatile Acer Chromebook Plus Spin 714

By Robby Payne
December 10, 2025

The Google Pixel 9a just hit its lowest price ever at $150 off

By Joseph Humphrey
December 8, 2025

At $349, this Lenovo Chromebook Plus is one of the best value laptops you can buy

By Joseph Humphrey
December 3, 2025

More Deals

Xremove ads

Reviews

Acer Chromebook Plus Spin 514 Review: Kompanio Ultra power in a convertible

By Robby Payne
December 24, 2025

My review after 6 weeks with the Lenovo Chromebook Plus 14 [VIDEO]

By Robby Payne
August 11, 2025

One week with the best small Android tablet you can buy, and I’m sold

By Robby Payne
May 9, 2025

Best Chromebooks of 2024 [VIDEO]

By Robby Payne
November 28, 2024

Samsung Galaxy Chromebook Plus Review: Samsung is back! [VIDEO]

By Robby Payne
October 28, 2024

More Reviews

Xremove ads

Guides

This Chromebook trackpad shortcut is definitely not new, but is blowing my mind

By Robby Payne
March 11, 2024

How to reduce broadcast delay on YouTube TV to stop live spoilers

By Robby Payne
December 8, 2023

Windows PC keyboard and Chromebook

How to use a Windows keyboard with a Chromebook

By Joseph Humphrey
December 8, 2023

How reset and revert your Chromebook to the previous version of Chrome OS

By Robby Payne
November 29, 2023

My Chromebook Plus features disappeared: here’s how I fixed it

By Robby Payne
November 24, 2023

More Guides

TWITTER · FACEBOOK · INSTAGRAM · YOUTUBE · EMAIL · ABOUT

Copyright © 2025 · Chrome Unboxed · Chrome is a registered trademark of Google Inc.
We are participants in various affiliate advertising programs designed to provide a means for us to earn fees by linking to affiliated sites.

PRIVACY POLICY