#mellowtel
Google has removed a cluster of Chrome extensions from the Web Store that enrolled user browsers into a web-scraping botnet

Security firm Spur says the number of Mellowtel proxy nodes fell from 90,000 to 18,000 after Google's action

spur.us/blog/mellowt...
September 23, 2026 at 9:28 PM
segue lista de extensões para chrome, firefox e edge que embutiram um script que fica lendo páginas da internet para alimentar treinamento de alguma IA
Extensions using Mellowtel
docs.google.com
July 10, 2025 at 6:07 PM
Seems John Tuckner (one of the original reporters) actually managed to make a list of KNOWN users of the library.
Here:
docs.google.com/spreadsheets...
Extensions using Mellowtel
docs.google.com
July 14, 2025 at 5:14 PM
-Latvia arrests hacker
-Ryuk member gets two years in prison
-Coinbase phisher gets 12 years
-Rydox admin pleads guilty
-Meta bans scammer accounts and pages
-Hacker uses AI to steal 600k credit cards
-Google goes after Mellowtel botnet
-Storm-2570 profile
-UNK_CondorFiltration targets LATAM
September 25, 2026 at 8:03 AM
The software library we're talking about here is specifically called Mellowtel, used by extension developers to get 💵kickbacks for scraping data.

It's not obvious to us how to get a list of extensions that use Mellowtel.
bsky.app/profile/arch...
arstechnica.com/security/202...

the company providing the library/disservice that's integrated into browser extension is called Mellowtel
July 14, 2025 at 5:00 PM
『これらの調査結果からタックナー氏はMellowtelにプライバシー侵害やセキュリティリスクの懸念があると主張しています。』

ユーザーのネット環境の「余った帯域幅」をAI企業のクローラーに流用して収益化するライブラリが存在し245種のブラウザ拡張機能に組み込まれている
gigazine.net/news/2025071...
ユーザーのネット環境の「余った帯域幅」をAI企業のクローラーに流用して収益化するライブラリが存在し245種のブラウザ拡張機能に組み込まれている
アプリ開発者の収益化を助けるとされるライブラリ「Mellowtel」が存在し、ユーザーネットワーク帯域幅をAI企業に提供して見返りとして金銭を得ていることが話題になっています。Mellowtelについてはプライバシー侵害やセキュリティリスクの懸念も浮上していますが、Mellowtelの開発者は疑惑を否定しています。
gigazine.net
July 11, 2025 at 7:28 AM
ユーザーのネット環境の「余った帯域幅」をAI企業のクローラーに流用して収益化するライブラリが存在し245種のブラウザ拡張機能に組み込まれている
https://gigazine.net/news/20250711-mellowtel-browser-crawler/
ユーザーのネット環境の「余った帯域幅」をAI企業のクローラーに流用して収益化するライブラリが存在し245種のブラウザ拡張機能に組み込まれている
アプリ開発者の収益化を助けるとされるライブラリ「Mellowtel」が存在し、ユーザーネットワーク帯域幅をAI企業に提供して見返りとして金銭を得ていることが話題になっています。Mellowtelについてはプライバシー侵害やセキュリティリスクの懸念も浮上していますが、Mellowtelの開発者は疑惑を否定しています。
gigazine.net
July 11, 2025 at 4:31 AM
#mellowtel browser extension. == residential proxy malware.

Just don't. it's like giving your browser an STD.

More here from #spur

spur.us/blog/mellowt...
spur.us
September 24, 2026 at 3:17 AM
arstechnica.com/security/202...

the company providing the library/disservice that's integrated into browser extension is called Mellowtel
July 14, 2025 at 12:12 PM
Here's the list of browser extension which are compromised with a javascript library that can expose and 𝘴𝘦𝘭𝘭 your data.
[Browser] Extensions using Mellowtel [Library] : Sheet1
docs.google.com/spreadsheets...
Extensions using Mellowtel
docs.google.com
July 9, 2025 at 10:47 PM
Més d’un milió d’usuaris han instal·lat extensions que converteixen els navegadors en bots.

Les extensions contenen una biblioteca anomenada Mellowtel que espera que els usuaris estiguin inactius, per tal de fer scraping a pàgines i enviar els resultats.
secureannex.com/blog/mellow-...
Mellow Drama: Turning Browsers Into Request Brokers
How the Mellowtel library transforms browser extensions into a distributed web scraping network, making nearly one million devices an unwitting bot army.
secureannex.com
July 9, 2025 at 6:26 AM
Media Downloader, liked good at first. However, it's loaded down with some kind of AI bloatware called mellowtel which "uses [Read: Leeches] a fraction of [your] unused internet" to "train their AI models". Don't download this AI miner to your computer!
October 20, 2024 at 10:16 PM
How the Mellowtel library transforms Browser Extensions into a distributed Web Scraping Network, making nearly 1 Million Devices an unwitting Bot Army - Technical report by John Tuckner secureannex.com/blog/mellow-...
Mellow Drama: Turning Browsers Into Request Brokers
How the Mellowtel library transforms browser extensions into a distributed web scraping network, making nearly one million devices an unwitting bot army.
secureannex.com
July 11, 2025 at 7:10 PM
There are browser extensions that scrape everything you view and sell it to AI companies #datasec #mellowtel arstechnica.com/security/202...
Browser extensions turn nearly 1 million browsers into website-scraping bots
Extensions load unknown sites into invisible Windows. What could go wrong?
arstechnica.com
July 12, 2025 at 1:04 PM
🚨 ICYMI - 245 browser extensions contained a code library called Mellowtel which allows anyone to make requests through your browser while extension owners get paid. This has impacted over 900,000 users! Let's take a look at how it works! 👇
July 8, 2025 at 7:29 PM
Nearly 1,000,000 browsers have become unwitting request brokers due to browser extension publishers including a monetization library called Mellowtel. Extensions utilizing the same permissions already accepted by users now load hidden iframes which connect to services for others. Blog 👇
July 7, 2025 at 2:03 PM
ユーザーのネット環境の「余った帯域幅」をAI企業のクローラーに流用して収益化するライブラリが存在し245種のブラウザ拡張機能に組み込まれている - GIGAZINE https://gigazine.net/news/20250711-mellowtel-browser-crawler/
July 11, 2025 at 7:36 AM
Browser extensions turn nearly 1 million browsers into website-scraping bots

MellowTel is also problematic because the sites it opens are unknown to end users. That means they must trust MellowTel to vet the security and trustworthiness of each site being accessed. And, of course, that security…
Browser extensions turn nearly 1 million browsers into website-scraping bots
MellowTel is also problematic because the sites it opens are unknown to end users. That means they must trust MellowTel to vet the security and trustworthiness of each site being accessed. And, of course, that security and trustworthiness can change with a single compromise of a site. MellowTel also poses a risk to enterprise networks that closely restrict the types of code users are permitted to run and the sites they visit.
nextbusiness24.com
July 10, 2025 at 8:11 AM
Perceptron Network, the largest extension using Mellowtel, has been removed by Google for malware. It loaded the scraper without opt-in on installation. Perceptron claims it is a mistake and is asks users to install manually now.

First identified here - secureannex.com/blog/mellow-...
July 23, 2025 at 9:13 PM
Want to know who is behind Mellowtel, the indicators you can hunt for, and the impacts to your organization? The latest @secureannex.com blog covers all of that.

secureannex.com/blog/mellow-...
Mellow Drama: Turning Browsers Into Request Brokers
How the Mellowtel library transforms browser extensions into a distributed web scraping network, making nearly one million devices an unwitting bot army.
secureannex.com
July 8, 2025 at 7:29 PM
Even if you didn't see the iframe loaded, you can inspect your browser console to see the requests made on your behalf. The iframe even takes the loaded content and returns it back to a Mellowtel domain and a Lambda function for further processing.
July 8, 2025 at 7:29 PM
How is this easily done? Well Mellowtel removes security headers which prevent this using the "declarativeNetRequest" permissions putting users at risk!
July 8, 2025 at 7:29 PM