Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found 27%

By Swati Khandelwal11%

7/13/2026, 5:17:24 PM

BS Summary: This article contains 30 faulty reasoning types, including Hasty Generalization, Indoctrination, and Appeal to Authority, with Post Hoc (False Cause) as the most egregious example at 16.6% saturation with 145 hits. Analysis detected 1,792 faulty-reasoning hits from 874 analyzed words, generating a BS Score of 38.5% and a BS Rank of 27% (15,796 of 21,568 articles). This article is better (less manipulative) than 73.20% of the article peer group.

Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. 
The collector was dormant. 
An empty allow-list kept it switched off, and no proof has emerged that it ever gathered or sent a single browsing domain. 
The analysis came from Stripe OLT, a UK security firm, which checked the code against Google's own Web Store signature and confirmed the collector shipped inside the genuine extension, not a counterfeit. 
Its review covers the Chrome build and its roughly 900,000 users; third-party trackers put another 700,000 or so on Edge. 
Microsoft pulled the Edge listing on July 3, and Google removed the Chrome one a week later, on July 10. 
Version 7.0.18 (extension ID idgpnmonknjnojddfkpgkljpfnnfcklj) still edits HTTP headers as advertised. 
The same minified background code also contains a second system. 
On first run, it builds a device fingerprint and loads a hardcoded encryption key. 
As you browse, it takes the domain from each page you open, encrypts it, and stores it locally, up to 1000 distinct domains. 
Once a day, a scheduler bundles the encrypted list with your fingerprint, posts it to api.stanfordstudies[.]com, and wipes the local copy. 
The upload time is offset per install, so browsers running it would not all beacon at once if the collector were switched on. 
Separate teardowns, by HackIndex on version 7.0.18 and researcher Yunus Aydin on 7.0.17, describe the same pipeline. 
Not everything was asleep. 
On install, update, and uninstall, the extension pinged a second domain, extensions-hub[.]com, with the product, version, and browser. 
And a script that runs on every page had already logged real request metadata to local storage in plain text, so that piece had clearly been running. 
Automated checkers had rated ModHeader low risk, some as high as 95 out of 100. 
Each part of the design can frustrate a different kind of check. 
The data is encrypted, so a scanner sees ciphertext. 
The upload is gated off, so a sandbox sees nothing leave. 
The malicious code is minified into a legitimate codebase. 
The endpoints had no established malicious reputation to flag. 
And a signed, popular extension reads as trusted. 
A store signature proves where a file came from, not what it does. 
Where the domains lead 
Stripe OLT tied the domains to real, maintained infrastructure. stanfordstudies[.]com has no link to Stanford; it is a repurposed old domain fronting an OpenSearch back end, while extensions-hub[.]com is set up for advertising. 
The two API endpoints resolved to the same Amazon server at the time of analysis, which fits one operator without proving it. 
A handful of weak signals point loosely toward a Chinese-speaking operator: a Simplified Chinese locale, a "salt" marker written with the character 盐, and a China-origin mail provider. 
The researchers name no group, and neither do we. 
The warning signs came earlier. 
ModHeader drew complaints for injecting ads into search results in 2023 and reportedly went ad-supported around then. 
Who took it over is unconfirmed, and the researchers make no claim about the original author. 
ModHeader's own site still publishes an ad plan that says it collects no user data, which is hard to square with a built-in browsing-history collector, even a switched-off one. 
The developer has not responded publicly to the findings as of publication. 
The Hacker News has contacted ModHeader for comment and put further questions to Stripe OLT, and will update this story with any response. 
In 2021, Brian Krebs described how popular extensions get quietly bought and turned into data pipes. 
This resembles that pattern, now with encryption and a gate that keeps scanners from seeing the upload. 
This year alone, a run of Chrome extensions was caught collecting data under an "anonymous analytics" label, and a separate set impersonated Workday and NetSuite to steal session cookies. 
Header editors and cookie managers need broad access to work, and when trust breaks, the blast radius is wide. 
What to do 
If you have ModHeader, remove it from Chrome and Edge; your browser may have disabled it already. 
Uninstalling clears its stored data, so the thing to double-check is that profile sync or a managed extension policy will not put it back. 
If you pasted secrets into it, API keys, bearer tokens, and session cookies, rotate them, since researchers found its header-history feature storing full HTTP headers on disk. 
For defenders, block and log stanfordstudies[.]com and extensions-hub[.]com at DNS and proxy, and search logs for the extension ID and any POST to api.stanfordstudies[.]com/app/log. 
Stripe OLT published ready-to-run KQL hunting queries for Defender and Sentinel. 
The takedowns handle this one extension. 
The design is the part that should worry people: a complete, store-verified collector sat inside a trusted, popular tool, one apparently built to switch on once an ordinary update populated the empty list. 
The automated scanners rated it low risk, and the next tool built this way may look just as clean. 
The practical lesson is narrow: extension review has to watch for dormant code paths that testing never triggers, new call-home endpoints, and a capability a routine update can add after a change of hands. 
Article reasoning-pattern comparisonThis article: 8.8%Swati Khandelwal: 2.4%The Hacker News: 2.0%Confirmation Bias8.8%This article: 2.3%Swati Khandelwal: 1.5%The Hacker News: 1.2%Anchoring Bias2.3%This article: 9.5%Swati Khandelwal: 3.5%The Hacker News: 3.3%Availability Heuristic9.5%This article: 8.2%Swati Khandelwal: 1.4%The Hacker News: 1.5%Representativeness Heuristic8.2%This article: 5.7%Swati Khandelwal: 0.7%The Hacker News: 0.6%Hindsight Bias5.7%This article: 3.8%Swati Khandelwal: 2.4%The Hacker News: 2.5%Overconfidence Bias3.8%This article: 5.8%Swati Khandelwal: 2.8%The Hacker News: 2.8%Framing Effect5.8%This article: 5.0%Swati Khandelwal: 0.9%The Hacker News: 1.1%Loss Aversion5.0%This article: 0.7%Swati Khandelwal: 0.7%The Hacker News: 0.6%Status Quo Bias0.7%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 3.9%Swati Khandelwal: 1.2%The Hacker News: 1.3%Optimism Bias3.9%This article: 7.7%Swati Khandelwal: 1.9%The Hacker News: 1.6%Pessimism Bias7.7%This article: 14.1%Swati Khandelwal: 6.3%The Hacker News: 6.7%Negativity Bias14.1%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 3.2%Swati Khandelwal: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias3.2%This article: 4.6%Swati Khandelwal: 0.4%The Hacker News: 0.5%Halo Effect4.6%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 5.6%Swati Khandelwal: 1.5%The Hacker News: 1.5%Recency Bias5.6%This article: 1.5%Swati Khandelwal: 0.2%The Hacker News: 0.2%Primacy Effect1.5%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 14.2%Swati Khandelwal: 4.0%The Hacker News: 4.1%Appeal to Authority14.2%This article: 0.0%Swati Khandelwal: 1.3%The Hacker News: 1.5%False Dilemma0.0%This article: 5.9%Swati Khandelwal: 0.7%The Hacker News: 0.5%Slippery Slope5.9%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 15.2%Swati Khandelwal: 3.8%The Hacker News: 4.3%Hasty Generalization15.2%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.2%Bandwagon0.0%This article: 1.9%Swati Khandelwal: 0.8%The Hacker News: 1.1%Appeal to Emotion1.9%This article: 3.3%Swati Khandelwal: 0.3%The Hacker News: 0.5%Begging the Question3.3%This article: 16.6%Swati Khandelwal: 2.0%The Hacker News: 1.9%Post Hoc (False Cause)16.6%This article: 1.4%Swati Khandelwal: 0.1%The Hacker News: 0.0%Tu Quoque1.4%This article: 7.4%Swati Khandelwal: 0.7%The Hacker News: 0.6%Burden of Proof7.4%This article: 0.9%Swati Khandelwal: 0.1%The Hacker News: 0.1%Appeal to Nature0.9%This article: 2.2%Swati Khandelwal: 0.3%The Hacker News: 0.3%Composition/Division2.2%This article: 9.4%Swati Khandelwal: 1.1%The Hacker News: 1.0%Anecdotal9.4%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%No True Scotsman0.0%This article: 11.3%Swati Khandelwal: 2.5%The Hacker News: 2.3%Ambiguity (Equivocation)11.3%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 0.0%Swati Khandelwal: 1.1%The Hacker News: 1.4%Unattributed Quote0.0%This article: 0.0%Swati Khandelwal: 0.8%The Hacker News: 1.0%Quote-first Misdirection0.0%This article: 10.1%Swati Khandelwal: 2.8%The Hacker News: 2.4%Biased Writer Voice10.1%This article: 14.8%Swati Khandelwal: 5.1%The Hacker News: 4.4%Indoctrination14.8%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 2.9%Attempt to Sell a Product or S…0.0%

874 words analyzed.

Speakers

3speakers13%attributed speech759writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 13 words • 0.0% coverageWriter's voice • 32 words • 100.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageStripe OLT • 32 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 27 words • 100.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageStripe OLT • 33 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 29 words • 100.0% coverageWriter's voice • 12 words • 0.0% coverageHacker News • 23 words • 0.0% coverageBrian Krebs • 16 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 3 words • 100.0% coverageWriter's voice • 17 words • 100.0% coverageWriter's voice • 24 words • 100.0% coverageWriter's voice • 27 words • 100.0% coverageWriter's voice • 24 words • 100.0% coverageStripe OLT • 11 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 33 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 34 words • 100.0% coverage
Selected voice

Brian Krebs

100%flagged-word coverage
16 attributed words14% of attributed speech85% writer coverage
0%10.0%20.0%Indoctrination-17.0 ptsWriter: 17.0%Brian Krebs: 0.0%0.0%Biased Writer Voice-11.6 ptsWriter: 11.6%Brian Krebs: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.