Hacker News new | ask | show | jobs
by eriknstr 3289 days ago
I recently found an interesting issue [1] filed in public on the GitHub repository of a fork of a popular extension.

Here are archived versions of the URLs mentioned in the issue:

Without "partner extension": http://archive.is/anu2E

With "partner extension": http://archive.is/bp93l

As is evident, what their "partner extension" does is in fact maliciously hijacking and replacing ad-space on websites visited by the user.

Strangely, searching for their name among the issues on GitHub does not show other such results. I guess they usually make contact directly and that the person at that company who filed this issue did not realize it would be visible to the public.

Here is the full text of the issue:

> Adnow is interested in byuiing your extension traffic #1

> Dear Kyong Tsu,

> My name is Anastasia, I am a manager from international advertising network Adnow.

> Extension traffic is a hot trend nowadays, and we are interested in buying traffic from Facebook Video Downloader extension and the others. We are ready to share an idea of monetization extensions with you and give you a method.

> We offer:

> * high payouts

> * 100% fill rate (we buy traffic from all over the world)

> * Integration through JS Tag / XML / JSON feed

> * Integration method

> That's how the page looks without partner extension: https://gyazo.com/5d635a9dc7bdc142e18e6775a1d1340d

> And that's how it looks for user with our plugin/code in extension: https://gyazo.com/a2b48b16d304a3ba37cdf6967fa4d9d8

> Please contact me in case you are interested in monetization your extensions.

> I am looking forward to your answer.

> Thank you in advance.

> Best regards,

> --

> Anastasia Nova

> Sales manager | Adnow LLP

> e.: tasya@sales.adnow.com

> Skype: tasya@adnow.com

[1]: https://github.com/KyongTsu/TabMemorySaver/issues/1

Archived snapshot of above issue: http://archive.is/Z5mJl