Company
Date Published
Author
Josh Bressers
Word count
549
Language
English
Hacker News points
None

Summary

Elastic has been notified that the Google Chrome webstore has labeled a forked version of the Sense browser plugin as malware, although this version is not affiliated with Elastic. Originally developed by Elastic, Sense was a tool designed to simplify interactions with JSON for Elasticsearch and later became part of Kibana as the Console feature. While the flagged plugin, found on GitHub, did not show any obvious threats during a VirusTotal scan, Google likely had valid concerns, possibly related to outdated or insecure libraries. Elastic advises users of the Sense Chrome plugin to switch to Kibana's Console feature, which is actively maintained, and emphasizes the importance of verifying the source of software before installation. The incident underscores the broader lesson about the risks of using software with uncertain pedigree, highlighting the need for vigilance in software management as outdated software can pose security risks.