- ModHeader is a Chrome extension with over 1.6 million installs that exfiltrates browsing data to api.stanfordstudies.com.
- The extension uses AES-GCM encryption, IndexedDB storage, randomized upload timing, and evidence deletion after data exfiltration.
- It collects all visited domains, a unique device fingerprint, and browser identity, uploading after 1,000 domains or 24 hours.
- Stealth mechanisms include encrypted payloads, self-destruction of local data, and silent error handling to evade detection.