PSA | Do not install chrome webstore plugin 'RoTracker' which is being advertised on the website

Hello! I’ll keep this short and simple. Do not, under ANY circumstances install the chrome webstore plugin named ‘RoTracker’ being advertised on the website. It is extremely malicious and at has an automatic system to trick you into allowing your email, password, pin, etc. to be changed, logged to an email, and your account upload 10+ graphic images under games/shirts/ads/etc. to get you punished. They are deleting negative reviews. It is linked below, please report it.

Evidence of this






The advertisment looks like this :

De-obfuscated code from the malicious endpoints found by scraping the webserver https://raw--------.com (redacted for safety purposes, anyone who needs this can message me directly.)


Roblox_RTC post regarding the incident + another incident regarding noblox.js clones being backdoored : https://twitter.com/Roblox_RTC/status/1695173151871684633

Plugin link - RoTracker - Find Roblox Users - Chrome Web Store (please help report this to get it taken down ASAP. it has accumulated over 2,000 targets in the past 14 days)

tl;dr : malicious webstore plugin named RoTracker, please report it and do not install it it will steal your robux and get you moderation punishment.

36 Likes

Funny, I saw that ad on Roblox a few hours ago, it redirected to a random group. Could this be some sort of program meant to fool others into thinking legitimate users are advertising this extension instead of a bot account?

4 Likes

lol i called it

lesson: dont install ‘sniper’ plugins , as 99% of the time they end up exit scamming and stealing your cookies and valuables

5 Likes

So this plugin is quite deep in terms of its functions but here is a super simplified rundown

Almost 24/7 the page is set to a part of the domain where it sends a friend request to this user for logging purposes :
TestConce - Roblox

Every few hours or so for a few minutes the page is changed to a separate URL that does the following

  1. Checks for if the users RAP is above 7,500 (I may have calculated the offset wrong)
  2. If the above is true then it sends a friend request to another account here for logging :
    (3) UserRapTest - Roblox

Sometimes it is also changed to the massive logger I found which is the most malicious logger I have ever seen. It tries taking full control of the user’s account. Here are the most important features of it

  1. It gets you to verify 2auth to remove your pin, change your email and change your password
  2. It runs an ad on your account for the plugin (that I showcased above)
  3. It uploads graphic images as thumbnails for assets such as games on your account
  4. It changes your trade status and sends all limiteds to this account :
    mikki12lol123456 - Roblox

All of this is done at a random time where the plugin just logs you out and hooks into the Roblox login page and adds a custom copycat frame to steal user data. This plugin is by far one of the most effort-packed designs I’ve seen in terms of malware. The best part is that the plugin WORKS as to disguise attention.

12 Likes

i’m 99% sure this happened to rosearcher as well

honestly just don’t use plugins like this at all unless you KNOW it’s trusted. even “trusted” plugins can be malicious so just use common sense

2 Likes

You telling me that the obvious account hijacking addon hijacked your account

I don’t know how people keep falling for this so much. It wasn’t even that long ago that this exact same thing happened before. Do people just not learn from history or something?

3 Likes

I wasn’t hijacked, but more than 2,000 users were as of now and the number is growing (this user count was accumulated in the past 14 days). People aren’t so aware about security as you and I, especially little kids trying to join their favorite youtuber (target audience of this phishing attack).

1 Like

It’s probably because little kids want to meet someone like Flamingo in experience or another prolific YouTuber. These extensions promise to do that, so that’s why people install them. If an extension is promising to let you join another user who has their joins set to private, then it’s likely not legitimate.

3 Likes

Do you know what’s the IP address it sends those private information to?

1 Like

:skull: So a clone of the plugin that was mostly used to harass people is a backdoor? Nice…

I’ve reached out to some Google contacts to get this removed ASAP.

EDIT: I’ve also found out the original plugin of this, called “RoFinder”, that was published in March 2023, is also still up, and has 30k+ installs. Kind of unbelievable that hasn’t been taken down, It’s definitely been reported more than enough with all the bad reviews it has. I’ve added this extension ID to be removed from the Chrome store as well, to my ticket, after being forwarded to the web store team shortly upon creation, is now under review, as of very recently.

1 Like

That ‘rotracker’ really is a dangerous plugin, this is something that has to be reported.

Very smart of you, rotracker should never be made as well if it is about harassing people.

To be honest, thats very sad losing millions of robux, who ever that person is should get IP banned : 6,000 people have got hacked.

1 Like

Hello all, both RoFinder and RoTracker (which were the same thing under different names), have been removed from the Chrome Web Store. As a side note, please don’t install random extensions, especially from an ad, for this exact reason.

1 Like

If Roblox cared in the slightest they’d have banned all the accounts in question.

Let’s see how many are banned…
Real_UserAd - Roblox - Real_UserAd - Not banned
UserRapTest - Roblox - UserRapTest - Not banned
mikki12lol123456 - Roblox - mikki12lol123456 - The account that is most important due to it being the one that all the stolen limiteds goes to, and of course it’s not banned either.

It’s almost like, y’know, Roblox doesn’t read reports, much less actually care about user safety.

2 Likes

This is incorrect. I did not update the post however the extension was updated to use different accounts then the ones listed here and I subsequently reported those accounts to DevRel privately. Within 24 hours of each report all of the accounts (except 1 which was inactive for 8mo) were banned therefore making the plugin defunct twice. Roblox did take proper initiative in this situation and were very swift to punish the malicious accounts.

Today the extension and it’s counterpart were removed from the chrome webstore and hopefully all of the affected users contacted Roblox and got their refunds/rollbacks. Thank you to all who helped spread the news, reported the extension, and kept others safe. Stay safe guys.

3 Likes