Dormant Collector in ModHeader: why the removal of a 1.6M-install extension is a critical cybersecurity signal

Colleagues, I’d like to flag a cybersecurity development. Google and Microsoft removed the ModHeader extension from Chrome and Edge after researchers found a hidden browser-history collector in the official build.
A few points stood out to me:
- the collector was embedded in a legitimate, signed extension;
- it was not active because the allow-list was empty, but the code was already on devices;
- the extension also contained local logs and calls to external domains.
Why this matters: trust in a store signature is not the same as trust in code behaviour.
Do you review extensions for “sleeping” functions after updates?
#cybersecurity #browsersecurity #supplychain #privacy

