|
|
|
|
|
by Dedime
1846 days ago
|
|
The code is calling out to a malicous URL for a script, downloading it, and executing the script. The malicious script from the URL is mirrored here: https://archive.is/TxFWj Nobody has figured out exactly what it's doing quite yet, but you can paste that code into a Javascript deobfuscator and try to figure it out yourself: https://lelinhtinh.github.io/de4js/ Based off of reading the code for 5 minutes with my very poor javascript skills, it's modifying your searches via Google / Bing and redirecting you to a practically unknown search engine called "Blacksearch". Very suspicious. I found a reddit thread with others complaining about this search engine, https://old.reddit.com/r/edge/comments/kzwb6q/redirecting_to... |
|
I could see this working on Karen who downloaded a coupon extension. But surely the type of person who installs an extension to force old.reddit.com will realize what’s happening almost immediately.
What is the point of malware if it can be caught so easily? This makes me wonder if maybe the dev didn’t do it on purpose. Maybe they sold it to an unscrupulous (and dumb) company, or maybe their build process is somehow infected.