Live data from Hacker News

JSON formatter Chrome plugin now closed and injecting adware

github.com

81–90 of 146 posts

Re: JSON formatter Chrome plugin now closed and injecting adware

#81

From the author on HN a couple years ago: > FWIW, and since a few of you probably use it… I own the JSON Formatter extension [0], which I created and open-sourced 12 years ago and have maintained [1] ever since, with 2 million users today. And I solemnly swear that I will never add any code that sends any data anywhere, nor let it fall into the hands of anyone else who would. I’ve been emailed several tempting cash o…

You either die a hero, or live long enough to become a villain.

Re: JSON formatter Chrome plugin now closed and injecting adware

#82
They responded on the Chrome store.

Hey William, thanks for flagging this! We were experimenting with analytics to help us identify crashes and improve stability. We've rolled this back in v2.1.17, which is now live and being rolled out. Going forward, we'll ensure any analytics collection is clearly disclosed. Thanks again!

https://chromewebstore.google.com/detail/json-formatter/gpmo...

Re: JSON formatter Chrome plugin now closed and injecting adware

#83
It is closed source because they think people want to buy this? Isn't this just built in to Firefox and Chrome now? I mean chrome already lets you preview API calls with pretty print.

I'm confused why this extension still exists I guess, and definitely too spooked out to even bother looking.

Re: JSON formatter Chrome plugin now closed and injecting adware

#85
post #40
post #36

Earlier quoted context omitted.

Depends on the personal situation. An extension with 2 million users can generate a very meaningful revenue. My extension has only 300k users, but offers that I received over years [0] would have been significant in some lower-income country. [0] https://github.com/extesy/hoverzoom/discussions/670

Extracts from two different offers: For example, your income for the 10k users will be ~ $ 1000 per month, users 20k ~ $ 2000 per month… 100к users ~10 000 $, and so on. ARPDAU (Average Revenue Per Daily Active User) basis - In average we have $0.007-0.011/user, US is $0.018.

Surely it's reasonable to assume that a company doing some dubious 'marketing intelligence' scraping of people's data from a Chrome plugin is going to both inflate the numbers they put in offers and try to scam their way out of paying if you actually accept. I wouldn't consider them real offers. They're marketing. The real world payments, if you get them, would be lower.

Re: JSON formatter Chrome plugin now closed and injecting adware

#86

From the author on HN a couple years ago: > FWIW, and since a few of you probably use it… I own the JSON Formatter extension [0], which I created and open-sourced 12 years ago and have maintained [1] ever since, with 2 million users today. And I solemnly swear that I will never add any code that sends any data anywhere, nor let it fall into the hands of anyone else who would. I’ve been emailed several tempting cash o…

You either die a hero, or live long enough to become a villain.

[deleted]

Re: JSON formatter Chrome plugin now closed and injecting adware

#87
Google spent all that time pushing Manifest V3 but does little to prevent this, and in some cases even encourages it. [1]

> To provide a more tangible example, Chrome Web Store currently has Blaze VPN, Safum VPN and Snap VPN extensions carry the “Featured” badge. These extensions (along with Ishaan VPN which has barely any users) belong to the PDF Toolbox cluster which produced malicious extensions in the past. A cursory code inspection reveals that all four are identical and in fact clones of Nucleus VPN which was removed from Chrome Web Store in 2021. And they also don’t even work, no connections succeed. The extension not working is something users of Nucleus VPN complained about already, a fact that the extension compensated with fake reviews.

[1] https://palant.info/2025/01/13/chrome-web-store-is-a-mess/

Re: JSON formatter Chrome plugin now closed and injecting adware

#88
post #87

Google spent all that time pushing Manifest V3 but does little to prevent this, and in some cases even encourages it. [1] > To provide a more tangible example, Chrome Web Store currently has Blaze VPN, Safum VPN and Snap VPN extensions carry the “Featured” badge. These extensions (along with Ishaan VPN which has barely any users) belong to the PDF Toolbox cluster which produced malicious extensions in the past. A cur…

[deleted]

Re: JSON formatter Chrome plugin now closed and injecting adware

#89

From the author on HN a couple years ago: > FWIW, and since a few of you probably use it… I own the JSON Formatter extension [0], which I created and open-sourced 12 years ago and have maintained [1] ever since, with 2 million users today. And I solemnly swear that I will never add any code that sends any data anywhere, nor let it fall into the hands of anyone else who would. I’ve been emailed several tempting cash o…

Good for him.

Re: JSON formatter Chrome plugin now closed and injecting adware

#90
post #56
post #54

Earlier quoted context omitted.

> went closed source and started injecting adware into checkout pages ... [and] geolocation tracking. Maybe we should resort to blame and shame publicly this sort of actions. DDoS their servers, fill their inbox with spam, review-bomb anything they do. Public court justice a la 4chan trolling. Selling out is a lawful decision, of course, but there is no reason it shouldn't come with a price tag of becoming publicly h…

Calm down, just spreading the word that the extension is adware and having everyone uninstall it is sufficient to demonstrate that this move was a mistake. Trying to ruin someone's life is going completely overboard. Repercussions should be proportionate, you don't shoot people for stealing a candy bar.

Agreed. Times are tough. Open source is under-appreciated. People are going to crack and slip up like this. We’re only human.
Post reply on HN