/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

A look at web proxy service Infatica, part of a growing industry of firms offering to buy browser extensions or pay their developers to include some extra code

Krebs on Security Brian Krebs

Context & Ripple Effects

Infatica's pitch to developers is the latest turn in a decade-long pattern of extensions monetizing their users rather than serving them. Google's disabling of 192 deceptive Chrome extensions carrying ad injectors set the enforcement template back in 2015, and the Nacho Analytics leak that exposed names and passwords from up to 4M installs showed how much sensitive data extensions can siphon even without malicious intent.

What Infatica adds is an acquisition market: firms now openly offer to buy extensions outright or pay developers to bolt on extra code. The buyers' demand side is visible in later reporting — researchers found cybercriminals shifting from bulletproof hosts to residential proxies that disguise malicious traffic as normal activity, and by 2025 extensions were being repurposed at scale, from 245 extensions overriding security protections to scrape websites to ones caught harvesting users' AI chatbot conversations.

First-order effects

  • Extension developers face standing offers to sell out or embed third-party code, meaning a popular extension's install base can be converted into proxy capacity overnight — often without users understanding what they agreed to.
  • Users of acquired extensions become unpaid infrastructure: their home IPs and bandwidth are resold as residential proxy traffic to customers they never chose.

Second-order effects

  • Criminals gain a cleaner supply chain for hiding malicious traffic, accelerating the shift away from bulletproof hosting toward residential proxies that blend into ordinary consumer traffic.
  • Google and Mozilla face harder review problems: code added post-acquisition or via updates can transform a benign extension, so vetting at submission time no longer guarantees what ships.

Third-order effects

  • If the acquisition-and-embed model keeps paying, trust in the extension ecosystem structurally decays, pushing security-conscious organizations toward controlled alternatives like the enterprise browsers Island and Here that bake security controls into the browser itself.
  • Consumer bandwidth and IP addresses become a commoditized input market, with brokers like Infatica sitting between millions of unaware households and buyers ranging from scrapers to criminals.

The trend: Browsers are being quietly converted into rented infrastructure, as proxy brokers pay extension developers to turn user devices into residential network capacity.

Discussion

  • @garwarner @garwarner on x
    How safe is your Browser Extension? @briankrebs exposes a network of 10 million browsers being used for “proxying” after their owner's computers became party of a proxy #botnet by installing a seemingly useful browser extension. ==> https://krebsonsecurity.com/ ...
  • @briankrebs @briankrebs on x
    A company that rents out access to more than 10 million Web browsers so that clients can hide their true Internet addresses has built its network by paying browser extension makers to quietly include its code in their creations. https://krebsonsecurity.com/ ...