Approximately half an hour ago, I became aware that the version of Oracle distributed on the Chrome Web Store contained code that logged usernames and passwords on login, at the very least. (I’m not near a laptop and haven’t done a full code diff).
Oracle has been unpublished so it should be disappearing, but uninstall it NOW.
This code isn’t present on GitHub or v0.1.8, the last update I pushed out. The current compromised version is “v0.1.9” and Chrome Webstore says it was pushed on 10/3/17.
If you have used Oracle since then, you need to CHANGE YOUR PASSWORD NOW. If you have used this password on another site, you need to change it as well.
The extension is permissions wise scoped to Epicmafia.com, so any activity on any other site should not be affected.
At this moment I do not know how my account was breached and the compromised extension uploaded, nor do I know how access to Epicmafia.net was accessed (if at all). I will update in this thread as I further investigate.