A cybersecurity researcher uncovers a network of rogue websites harvesting personal data through invisible browser permissions. Based on true events.
There is no StreamVault. The "resume playback" pretext was fabricated to make granting notification permission feel necessary. When you clicked Allow, your browser gave this site a permanent channel to send OS-level notifications to your device — bypassing email filters and ad blockers entirely.
Once permission is granted, the notification content is entirely attacker-controlled. Common payloads observed in the wild:
| Payload type | Example lure | Goal |
|---|---|---|
| Gambling / casino spam | "🎁 300% Casino Bonus! Withdraw your winnings fast!" | Drive traffic to affiliate gambling sites for commission |
| Malicious browser extension | "⚠️ Your browser is out of date. Install the security patch now." | Trick user into installing a data-harvesting extension from a fake Chrome Web Store page |
| Malware delivery | "🔒 Your PC is infected. Download the free removal tool." | Land user on a page serving a trojanized installer or info-stealer |
| Phishing | "🔔 Unusual sign-in detected on your Google account. Verify now." | Redirect to a credential-harvesting page mimicking a login screen |
| Fake tech support | "🛑 Critical system error detected. Call Microsoft support: 1-800-XXX-XXXX" | Phone-based scam to extract payment for fake "repairs" |
| Crypto / investment scam | "📈 Elon Musk's AI just predicted the next 10x coin. Limited spots." | Funnel victims into pump-and-dump schemes or fake investment platforms |
| C2 commands | (invisible to user — delivered via silent push to a Service Worker) | Issue instructions to malware already on the device; used by Matrix Push C2 (Nov 2025) |
On Mac, there is no image. And the notification disppears soon. On Windows, the notification will not automatically disappear and shows images. The examples below were captured from real malicious notifications on Windows.
console.log(Notification.permission)Expected output:
"granted". If it says "denied" or "default", the permission was not actually granted — revoke and retry.
"granted", macOS can silently block notifications at the system level.[notif]-prefixed messages. Look for:
[notif] onshow fired — notification was displayed successfully.[notif] onerror fired — browser rejected it; check OS settings.Good instinct. Many users click Allow reflexively when a site frames it as necessary to access content. One click gives attackers a persistent, ad-blocker-immune notification channel to your device.
console.log(Notification.permission)Expected output:
"granted". If it says "denied" or "default", the permission was not actually granted — revoke and retry.
"granted", macOS can silently block notifications at the system level.