Chrome and Firefox extensions with up to 4M installs leaked sensitive data, including names and passwords, to marketing intelligence service Nacho Analytics
As many as 4 million people have Web browser extensions that sell their every click. And that's just the tip of the iceberg.
Context & Ripple Effects
This is the third major extension-store data scandal in four years: the [[a:877459|Web Of Trust add-on was pulled from every major store in 2016 after selling browsing histories]], and an AVG-installed Chrome extension exposed browsing data of 9M+ users the year before that. The difference here is severity — the payload includes names and passwords, not just clickstreams, and the buyer is a marketing intelligence vendor monetizing the data directly.
First-order effects
- Up to 4 million Chrome and Firefox users have extensions transmitting their clicks, names, and passwords to Nacho Analytics, whose subscribers can query that sensitive data.
Second-order effects
- Google and Mozilla face pressure to replicate the enforcement they later applied when removing 106 malicious Chrome extensions with 32M downloads, tightening store-level review of what extension code exfiltrates.
Third-order effects
- With the AVG, Web Of Trust, and Nacho Analytics incidents forming a repeated pattern, extension vetting shifts from per-developer trust to platform-enforced permission auditing, making the stores themselves the effective regulators of browser data flows.
The trend: Browser extension stores keep surfacing as bulk personal-data exfiltration channels, pushing Google and Mozilla toward treating store review as core privacy infrastructure rather than a curation afterthought.