Fake Copyright Notices Steal Google Credentials via Chrome Web Store
Key Takeaways A sophisticated phishing campaign is targeting Chrome extension developers with fake copyright infringement notices. The attackers aim to steal Google credentials by directing...
Key Takeaways
- A sophisticated phishing campaign is targeting Chrome extension developers with fake copyright infringement notices.
- The attackers aim to steal Google credentials by directing developers to highly convincing counterfeit Chrome Web Store login pages.
- Successful compromise could allow attackers to push malicious updates to popular extensions, impacting a wide user base.
- The scam leverages urgency and personalized details to appear legitimate, making it challenging to detect.
Sophisticated Phishing Targets Chrome Extension Developers
A new, highly deceptive phishing operation is actively targeting developers of Chrome extensions. This campaign utilizes meticulously crafted fake copyright removal notices that closely mimic official communications from the Chrome Web Store. The primary objective is to illicitly obtain Google credentials from unsuspecting developers.
Table Of Content
Detailed analysis of this threat, including a comprehensive report by Malwarebytes analysts, reveals the advanced nature of the scam. Developers are lured into entering their Google login information onto a counterfeit sign-in page, which poses a significant risk not only to their personal accounts but also to the millions of users who rely on their browser extensions. Given the widespread use of browser extensions in daily internet activities, such targeted attacks present a growing and critical security challenge.
Anatomy of the Attack
The phishing scheme begins with developers receiving an urgent notification, falsely claiming their extension is slated for removal due to copyright infringement. The message deliberately imposes a strict 48-hour deadline for an appeal, creating intense pressure for the victim to respond quickly and without thorough scrutiny.
The fraudulent appeal page is designed with extreme attention to detail, mirroring Google’s authentic communication style. It includes convincing elements such as a fabricated complaint number, a dynamic countdown timer, and a visual layout that faithfully replicates Google’s official branding. This level of sophistication is intended to trick even technically proficient developers, as highlighted in the Malwarebytes report shared with Cyber Security News (CSN).
The fake page is hosted on the domain dmca-chrome-extensions[.]click, which bears no affiliation with Google. Despite this, it presents itself as a “Chrome Web Store Developer Policy Center,” leveraging genuine Google branding to enhance its perceived legitimacy.
When a developer enters their extension ID into the deceptive page, the site dynamically retrieves public information related to that extension, including its real name, icon, and direct link to its Chrome Web Store listing. While this information is publicly accessible, its personalized presentation within the context of a fake complaint significantly enhances the illusion of authenticity. The scam integrates these legitimate details with a fabricated complaint number, a “date received,” and a real-time countdown, further escalating the sense of urgency and credibility.
A crucial component of the attack is the fake Google sign-in window that appears after a developer clicks “Continue to verification.” This window is remarkably convincing, displaying a padlock icon, a title bar, and an address that reads “accounts.google.com.” However, this is merely a graphical overlay embedded within the phishing page itself. The attackers have even customized its appearance to match the operating system (Mac or Windows) of the victim’s device, making it feel even more familiar and trustworthy.
A simple test can expose this deception: attempting to drag the fake sign-in window beyond the browser’s edge. A genuine system window would move freely, whereas this embedded graphic will stop at the browser’s boundary and disappear if the browser is minimized, revealing its true nature as an element within the page.
What You Should Do
- Verify All Communications: Never trust warning emails that demand immediate action. Always navigate directly to your Chrome Web Store developer dashboard to check for official notifications about your extensions. Authentic policy notices will always appear within your official dashboard, not on external websites.
- Be Wary of Urgency: Treat any message that employs countdown timers or strict deadlines to compel rapid action with extreme skepticism. Legitimate policy review processes typically do not impose such immediate pressure.
- Inspect the URL Bar: Before entering any login credentials, meticulously examine your browser’s address bar. Ensure the domain is genuinely
accounts.google.comand not a deceptive look-alike, such asdmca-chrome-extensions[.]click. - Enable Two-Step Verification (2SV): Implement strong two-step verification using a passkey or a hardware security key. This provides a critical layer of defense, as a stolen password alone would be insufficient for an attacker to gain access to your account.
- Post-Compromise Actions: If you suspect you have entered your credentials on a phishing page, immediately change your Google password. Log out of all active sessions across all devices and thoroughly review your Chrome Web Store listings for any unauthorized updates or new versions that you did not publish.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | dmca-chrome-extensions[.]click | Fake Chrome Web Store phishing page used to harvest Google developer credentials |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.