Browser extensions were also one of the biggest ways to distribute malware. The situation was genuinely horrific. Malware distributors would offer popular extension devs millions of dollars to buy the extension, then silently insert malware which gets auto deployed to millions of people.
But why blame the extensions instead of the auto-update feature? Wouldn't it be more effective to build external code review practices around the extension eco-system? For example, if you want to publish or update an extension, you first have to review someone's elses or something along those lines.
That sounds more like an issue with the update policies.
Why haven't they been prosecuted? And why hasn't this "cindyllm" bot account been deleted yet? Clearly a shadowban didn't send the message.
[dead]