This hijack script included Google Chrome and hosted Cloudflare via http://unpkg.com . @unpkg @heroku @cloudflare
I believe that no one is aware of that yet. @mjackson @reacttraining @cloudflare @googlechrome @googledevspic.twitter.com/3C3p8Es55Y
-
-
-
It's also redirecting to other locations like bet sites or dating sites etc.
-
Seems it's injected by
@HotspotShield extension (nlbejmccbhkncgokjcmghpfloaajcffj : https://chrome.google.com/webstore/detail/hotspot-shield-vpn-free-p/nlbejmccbhkncgokjcmghpfloaajcffj …).pic.twitter.com/xg7zVeCdxO
-
Seems like that extension is doing something malicious? If you disable that extension, do things behave as you'd expect?
-
Yes it's. Without any permission, it's directing user to bet, porn or such sites. Also displaying ads in new tabs. I've removed it already.
End of conversation
New conversation -
-
-
let me know if you see anything further. I expect
@unpkg will be removing their malicious JS shortly? -
Do we need to blacklist a package?
End of conversation
New conversation -
-
-
dealt with.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
I had this issue earlier today. After resetting Chrome, everything seemed fine. However, I don't know if this is a virus or not.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.