Security Advisory - LRN-120000 - Malicious OneClass Chrome Extension
Malicious OneClass Chrome Extension May Send Email on Students' Behalf and also Attempts to Collect User Credentials (username and password).
Please notify your students immediately that this extension should not be installed! Blackboard is currently working on it and we'll keep you updated. Any student that has already installed the extension should uninstall it ASAP and contact the college's IT department to make sure it is fully removed. These students must also change their passwords ASAP.
The OneClass Chrome Extension is not available directly via search in the Chrome Extensions Store and students are being phished with the following link to install it:
During installation, the extension requests permissions to "Read and change all your data on the websites you visit". However, students may not closely read or fully understand the requested permissions before accepting them. The extension adds a button inside the Learn pages to "Invite Your Classmates to OneClass".
The plugin will email all the students in a students' class (utilizing Learn URLs and resources, which are functioning as designed) to promote the OneClass plugin/product. The plugin also has code that attempts to collect and send the users' credentials (both username and password). We are in the process of determining if the code is successful in doing so.
The email content is:
"Hey guys, I just found some really helpful notes for the upcoming exams for <University Name> courses at https://oneclass.com/s/signup. I highly recommend signing up for an account now that way your first download is free!"