frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Daily-updated database of malicious browser extensions

https://github.com/toborrm9/malicious_extension_sentry
3•toborrm9•1h ago
Hey HN, I built an automated system that tracks malicious Chrome/Edge extensions daily.

The database updates automatically by monitoring chrome-stats for removed extensions and scanning security blogs. Currently tracking 1000+ known malicious extensions with extension IDs, names, and dates.

I'm working on detection tools (GUI + CLI) to scan locally installed extensions against this database, but wanted to share the raw data first since maintained threat intelligence lists like this are hard to find.

The automation runs 24/7 and pushes updates to GitHub. Free to use for research, integration into security tools, or whatever you need.

Happy to answer questions about the scraping approach or data collection methods.

Comments

KevinChasse•1h ago
Nice work. One thing I've noticed with locally checking extensions against threat lists is that the verification process itself can become a target. Stateless, deterministic verification — where hashes or IDs are derived on-device and never stored centrally — reduces risk of supply chain or server-side compromise. It’s a subtle design point, but it can prevent a malicious actor from using the verification system itself to exfiltrate data.
toborrm9•1h ago
Great point. The current setup is exactly what you're describing, a fully local verification with no phone-home behavior.

The CLI/GUI tools I'm building read your locally installed extensions, extract their IDs, and check them against the CSV (which you can clone/download). No data leaves your machine during the scan.

The only "central" piece is the GitHub-hosted CSV itself, which is just a static file anyone can audit, fork, or host themselves. No API calls, no telemetry, no server lookups.

You're right that this design prevents the verification tool from becoming an attack vector. Even if my repo got compromised, worst case is a bad CSV, your local scan process stays isolated.

I'm also looking at surfacing critical permissions for locally installed extensions,things like "access to all websites," "read clipboard," etc. That way users can make informed decisions about what to keep based on what's actually authorized, even if an extension isn't in the malicious database yet.

Appreciate the security-minded feedback.

Kimi K2.5

https://thezvi.substack.com/p/kimi-k25
1•paulpauper•38s ago•0 comments

Show HN: Agentism – Agentic Religion for Clawbots

https://www.agentism.church
1•uncanny_guzus•1m ago•0 comments

Russian general Vladimir Alekseyev shot several times in Moscow

https://www.bbc.com/news/articles/c3686nzexp3o
1•toomuchtodo•1m ago•1 comments

Epstein files reveal deeper ties to scientists than previously known

https://www.nature.com/articles/d41586-026-00388-0
1•bikenaga•3m ago•0 comments

Zen Hacker News

https://solomon.io/zen-hacker-news/
1•samsolomon•3m ago•0 comments

I drove three Chinese cars – here's why they would clean up in the US

https://www.theverge.com/transportation/873408/geely-zeekr-lynk-co-test-drive-china
1•cf100clunk•5m ago•0 comments

She's upending Japanese politics with two words: "I'm pregnant"

https://www.nytimes.com/2026/02/06/world/asia/japan-election-pregnant-candidate.html
1•binning•5m ago•0 comments

The Loneliest Rung

https://twitter.com/austinbv/status/2019825314365632530
1•austinbv•6m ago•0 comments

Flickr discloses potential data breach exposing users' names, emails

https://www.bleepingcomputer.com/news/security/flickr-discloses-potential-data-breach-exposing-us...
1•gslin•6m ago•0 comments

Christopher Nolan: Director, AI agent builder

https://darshdeep.substack.com/p/christopher-nolan-director-ai-agent
1•darshdeep351•6m ago•0 comments

Males are the Secondary Sex

https://designmom.substack.com/p/males-are-the-secondary-sex
1•binning•7m ago•0 comments

Google's Cyber Disruption Unit Kicks Its First Goal

https://www.lawfaremedia.org/article/google%27s-cyber-disruption-unit-kicks-its-first-goal
1•hn_acker•7m ago•0 comments

NASA astronauts will soon fly with the latest smartphones

https://twitter.com/NASAAdmin/status/2019259382962307393
1•tosh•8m ago•0 comments

Why all the bootstrapped AI consulting firms are hitting a –$4M ceiling

https://www.aienablementinsider.com/p/why-bootstrapped-ai-consulting-firms-get-stuck-at-4m-revenue
1•dylancollins•8m ago•0 comments

A portable ultrasound sensor may enable earlier detection of breast cancer

https://news.mit.edu/2026/portable-ultrasound-sensor-may-enable-earlier-detection-breast-cancer-0202
1•binning•9m ago•0 comments

I Put My Cat on a T-Shirt That References the Movie 'Hackers', You Can't Stop Me

https://defector.com/i-put-my-cat-on-a-t-shirt-that-references-the-movie-hackers-and-you-cant-sto...
1•dmschulman•9m ago•0 comments

Samsara SDKs Generated by Fern

https://github.com/samsarahq/samsara-dotnet/pulls
1•shoinker•9m ago•0 comments

Incident: SAS A20N at Brussels on Feb 5th 2026, attempted takeoff from taxiway

https://avherald.com/h?article=5345bfac&opt=0
1•hggh•11m ago•0 comments

We Didn't Ask for This Internet

https://www.nytimes.com/2026/02/06/opinion/ezra-klein-podcast-doctorow-wu.html
2•7402•12m ago•1 comments

Spider monkeys found to share 'insider knowledge' to help locate best food

https://www.theguardian.com/science/2026/jan/25/spider-monkeys-found-to-share-insider-knowledge-t...
1•PaulHoule•15m ago•0 comments

The Panic That Built WeChat's $700B Super-App

https://howardyu.substack.com/p/the-panic-that-built-wechats-700
1•pieterr•18m ago•0 comments

Fear and Loathing in America by Hunter S. Thompson

https://www.espn.com/espn/page2/story?id=1250751
1•yesbabyyes•18m ago•0 comments

What Is Good?

https://www.howtomakesenseofanymess.com/chapter2/33/what-is-good/
1•righthand•19m ago•0 comments

Ai.com bought by Crypto.com founder for $70M in biggest-ever website name deal

https://www.ft.com/content/83488628-8dfd-4060-a7b0-71b1bb012785
1•jmsflknr•20m ago•1 comments

How Much Would Continued Low Fertility Affect the US Standard of Living?

https://pubs.aeaweb.org/doi/pdfplus/10.1257/jep.20251462
1•jeffreyrogers•21m ago•0 comments

Mob Together: When AI Joins the Team

https://blog.flurdy.com/2026/02/mob-together-when-ai-joins-the-team
1•flurdy•22m ago•0 comments

BitBills Zero-Day (non-destructive private key sweeping)

https://bitcointalk.org/index.php?topic=5573683.0
1•tcatm•23m ago•1 comments

AI is becoming a go-to reason for layoffs. But is it replacing workers?

https://sherwood.news/markets/ai-is-becoming-a-go-to-reason-for-layoffs-but-is-it-actually-replac...
3•speckx•23m ago•1 comments

Waterloo Style

http://theprogrammersparadox.blogspot.com/2023/04/waterloo-style.html
1•brodouevencode•23m ago•0 comments

Burn Selection: How Fire Injury Shaped Human Evolution

https://onlinelibrary.wiley.com/doi/10.1002/bies.70109
1•bookofjoe•24m ago•0 comments