Risky Bulletin Newsletter
July 09, 2025
Risky Bulletin: Browser extensions hijacked for web scraping botnet
Presented by
News Editor
More than one million users have installed browser extensions that turn their browsers into proxies for a web scraping botnet.
The extensions contain a library named Mellowtel that waits for users to go inactive, disables page security protections, and then loads a remote website inside a hidden iframe. The parsed/scraped website is then sent to a remote URL for analysis.
SecureAnnex found the Mellowtel library in 245 extensions for Chrome, Edge, and Firefox.