Chrome Extension with 100,000 Users Caught Pushing Cryptocurrency Miner (bleepingcomputer.com)
Catalin Cimpanu, reporting for BleepingComputer: A Chrome extension with over 105,000 users has been deploying an in-browser cryptocurrency miner to unsuspecting users for the past few weeks. The extension does not ask for user permission before hijacking their CPUs to mine Monero all the time the Chrome browser is open. Named "Archive Poster," the extension is advertised as a mod for Tumblr that allows users an easier way to "reblog, queue, draft, and like posts right from another blog's archive." According to users reviews, around the start of December the extension has incorporated the infamous Coinhive in-browser miner in its source code.
If the extension is surreptitiously stealing your cpu cycles and electricity to perform an activity that the authors did not explicitly ask permission, I would say that meets the definition of theft. File a criminal complaint and let the authorities chase them around.
Security is one justification, but the real problem is that the old extension model allowed extensions to hook into every part of the GUI. This meant that any change to the GUI at all could potentially break an extension. They tried patching this by keeping track of what version an extension was developed against, but in the end they felt that the system was fundamentally broken and was holding the whole project back. Personally, I share your frustration as the new model can't even accommodate seamlessly shifting the tabs over to the side, or adding a button to pop open the password manager. I'm hoping they continue to add capability.
W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.