Warning: “Easy Auto Refresh” extension tracks you

[Cross-posted from /r/Chrome.]

Using a local proxy I just discovered that the Chrome Extension "Easy Auto Refresh" tracked my every move. It sends GET pings for every web-page visit to the url starting with http://edatasales.com/sdk/?...

The url contains unique tracking information and location data. The information is sent unencrypted.

It appears that the tracking does not start right away after installation. Extension's store page is here: https://chrome.google.com/webstore/detail/easy-auto-refresh/aabcgdmkeabbnleenpncegpcngjpnjkc/reviews?utm_source=chrome-remove-extension-dialog

Here is the maker of the software: http://dummysoftware.com/easy-auto-refresh/?action=install&new=4.5

And more detail about the company: http://www.dummysoftware.com/about.html

Edit: here is the tand.js file from the extension where the tracking happens: https://pastebin.com/z9TQqGCZ

1 thought on “Warning: “Easy Auto Refresh” extension tracks you”

Leave a Comment