frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Daily-updated database of malicious browser extensions

https://github.com/toborrm9/malicious_extension_sentry
12•toborrm9•3h ago
Hey HN, I built an automated system that tracks malicious Chrome/Edge extensions daily.

The database updates automatically by monitoring chrome-stats for removed extensions and scanning security blogs. Currently tracking 1000+ known malicious extensions with extension IDs, names, and dates.

I'm working on detection tools (GUI + CLI) to scan locally installed extensions against this database, but wanted to share the raw data first since maintained threat intelligence lists like this are hard to find.

The automation runs 24/7 and pushes updates to GitHub. Free to use for research, integration into security tools, or whatever you need.

Happy to answer questions about the scraping approach or data collection methods.

Comments

KevinChasse•3h ago
Nice work. One thing I've noticed with locally checking extensions against threat lists is that the verification process itself can become a target. Stateless, deterministic verification — where hashes or IDs are derived on-device and never stored centrally — reduces risk of supply chain or server-side compromise. It’s a subtle design point, but it can prevent a malicious actor from using the verification system itself to exfiltrate data.
toborrm9•3h ago
Great point. The current setup is exactly what you're describing, a fully local verification with no phone-home behavior.

The CLI/GUI tools I'm building read your locally installed extensions, extract their IDs, and check them against the CSV (which you can clone/download). No data leaves your machine during the scan.

The only "central" piece is the GitHub-hosted CSV itself, which is just a static file anyone can audit, fork, or host themselves. No API calls, no telemetry, no server lookups.

You're right that this design prevents the verification tool from becoming an attack vector. Even if my repo got compromised, worst case is a bad CSV, your local scan process stays isolated.

I'm also looking at surfacing critical permissions for locally installed extensions,things like "access to all websites," "read clipboard," etc. That way users can make informed decisions about what to keep based on what's actually authorized, even if an extension isn't in the malicious database yet.

Appreciate the security-minded feedback.

politelemon•1h ago
Could Firefox extensions be included?
julius•40m ago
Super cool. Brave support by any chance? Using Linux, it found my Chrome, but thats not my primary browser.

The Waymo World Model: A New Frontier for Autonomous Driving Simulation

https://waymo.com/blog/2026/02/the-waymo-world-model-a-new-frontier-for-autonomous-driving-simula...
371•xnx•3h ago•222 comments

Show HN: I spent 4 years building a UI design tool with only the features I use

https://vecti.com
59•vecti•47m ago•23 comments

Microsoft open-sources LiteBox, a security-focused library OS

https://github.com/microsoft/litebox
210•aktau•5h ago•105 comments

Sheldon Brown's Bicycle Technical Info

https://www.sheldonbrown.com/
177•ostacke•4h ago•42 comments

Learning from context is harder than we thought

https://hy.tencent.com/research/100025?langVersion=en
53•limoce•3d ago•14 comments

Understanding Neural Network, Visually

https://visualrambling.space/neural-network/
145•surprisetalk•3d ago•19 comments

I now assume that all ads on Apple news are scams

https://kirkville.com/i-now-assume-that-all-ads-on-apple-news-are-scams/
792•cdrnsf•7h ago•352 comments

How to effectively write quality code with AI

https://heidenstedt.org/posts/2026/how-to-effectively-write-quality-code-with-ai/
11•i5heu•1h ago•1 comments

Hackers (1995) Animated Experience

https://hackers-1995.vercel.app/
249•todsacerdoti•6h ago•144 comments

The Monad Called Free

http://blog.sigfpe.com/2014/04/the-monad-called-free.html
41•romes•4d ago•15 comments

My AI Adoption Journey

https://mitchellh.com/writing/my-ai-adoption-journey
863•anurag•1d ago•349 comments

A new bill in New York would require disclaimers on AI-generated news content

https://www.niemanlab.org/2026/02/a-new-bill-in-new-york-would-require-disclaimers-on-ai-generate...
451•giuliomagnifico•10h ago•177 comments

Invention of DNA "Page Numbers" Opens Up Possibilities for the Bioeconomy

https://www.caltech.edu/about/news/invention-dna-page-numbers-synthesis-kaihang-wang
122•dagurp•9h ago•79 comments

Things Unix can do atomically (2010)

https://rcrowley.org/2010/01/06/things-unix-can-do-atomically.html
227•onurkanbkrc•14h ago•88 comments

TikTok's 'Addictive Design' Found to Be Illegal in Europe

https://www.nytimes.com/2026/02/06/business/tiktok-addictive-design-europe.html
505•thm•8h ago•381 comments

The overlooked evolution of the humble car door handle

https://newatlas.com/automotive/evolution-car-door-handle/
20•andsoitis•3d ago•32 comments

DNS Explained – How Domain Names Get Resolved

https://www.bhusalmanish.com.np/blog/posts/dns-explained.html
115•okchildhood•3d ago•37 comments

Systems Thinking

http://theprogrammersparadox.blogspot.com/2026/02/systems-thinking.html
237•r4um•14h ago•108 comments

Show HN: If you lose your memory, how to regain access to your computer?

https://eljojo.github.io/rememory/
3•eljojo•1h ago•1 comments

We tasked Opus 4.6 using agent teams to build a C Compiler

https://www.anthropic.com/engineering/building-c-compiler
679•modeless•1d ago•660 comments

Stay Away from My Trash

https://tldraw.dev/blog/stay-away-from-my-trash
145•EvgeniyZh•3d ago•55 comments

Claude Opus 4.6

https://www.anthropic.com/news/claude-opus-4-6
2230•HellsMaddy•1d ago•965 comments

Recreating Epstein PDFs from raw encoded attachments

https://neosmart.net/blog/recreating-epstein-pdfs-from-raw-encoded-attachments/
491•ComputerGuru•2d ago•178 comments

Nixie-clock using neon lamps as logic elements (2007)

https://www.pa3fwm.nl/projects/neonclock/
47•jacquesm•4d ago•8 comments

The Gnome Village: Treads fight, gnomes cooperate (2025)

https://happihacking.com/blog/posts/2025/the-gnome-village/
5•rapnie•5d ago•1 comments

Show HN: Daily-updated database of malicious browser extensions

https://github.com/toborrm9/malicious_extension_sentry
12•toborrm9•3h ago•4 comments

Animated Engines

https://animatedengines.com/
50•surprisetalk•23h ago•4 comments

Solving Shrinkwrap: New Experimental Technique

https://kizu.dev/shrinkwrap-solution/
31•spiros•16h ago•2 comments

Plasma Effect (2016)

https://www.4rknova.com/blog/2016/11/01/plasma
76•todsacerdoti•3d ago•14 comments

The time I didn't meet Jeffrey Epstein

https://scottaaronson.blog/?p=9534
355•pfdietz•1d ago•491 comments