Warning: Tumblr 250+ posts per day scam

Updated happygeek 0 Tallied Votes 455 Views Share

As with any online service that starts to get popular traction and experiences rapid growth, social network come micro-blog platform Tumblr has been the target of just about every kind of scam and attempted cyber-criminal subversion out there inclduing some of its own making. Most of the time it's not worth reporting on these as they fall into the 'same old, same old' category, and if we did then DaniWeb would be so awash with scam warnings that every other posting would be drowned into obscurity. However, this one is worthy of our attention.

Not least as it seems to be catching a lot of folk out, rather sadly. It's doing this by using that tried and tested methodology of telling a user that there's a way to cheat the system and get something in terms of functionality that The Powers That Be don't want you to have. In this case that something is the ability to post more than 250 times in a single day.

Yep, as Tumble 'power-users' will be all too aware there are limits on the number of posts you can roll, and that daily posting limit would appear to be 250 for the typical user. Even though, in reality, for all but the most prolific poster and the spamming fraternity, 250 is probably quite enough thank you very much; when faced with a limit we all want to break it as that's our nature. And so it is that there has been a spate of people offering a tool to post more than 250 times a day, a browser extension that will remove the limitation completely.

It is, of course, nonsense and will do nothing of the sort. What it will do, according to security researchers at Malwarebytes, is harvest your login data via a keylogger and send encrypted data back to the originator as well as uploading random desktop screen images to a remote host. Go check out the link for more technical detail, and in the meantime don't be fooled by extensions that promise to deliver the undeliverable. Sure, there is going to be software out there that can alter aspects of the UI for social networks within the client browser. But, before downloading anything you should always apply due diligence and go search online for the facts. Don't be an early adopter, instead be a wise old owl who bides their time and lets the wisdom of crowds come to the fore...

Dani AI

Generated

Echoing ’s useful warning (and the appreciative replies from , , and ), this thread documents a classic social‑engineering pattern: browser extensions that promise to “bypass limits” are commonly used as a lure. Treat any extension that claims to change service limits or access private features with suspicion; check the publisher, recent reviews, the exact permissions requested, and whether the extension is trusted by the browser’s store before installing. ()

Immediate remediation (if a suspicious extension was installed): remove the extension from the browser’s extension/add‑on manager, then reset or audit browser settings. For Chrome use More → Extensions → Manage extensions (or right‑click the icon → Remove); for Firefox use Add‑ons Manager (about:addons) and Troubleshoot/Refresh mode if removal fails; for Edge use Extensions → Manage extensions → Remove. If the extension is corrupted or reappears, consider resetting the browser to defaults and clearing cache/cookies. ()

Account hardening for the Tumblr account named in the thread: change the Tumblr password to a new, unique, strong password; enable two‑factor authentication and save backup codes; review recent posts/changes and connected sign‑in methods; follow Tumblr’s account‑recovery and hacked‑account guidance if access was lost or settings were changed by another party. These steps reduce risk even if credentials were exposed. (help.tumblr.com)

System cleanup and follow‑up: run a full malware sweep (built‑in Defender tools or Microsoft Safety Scanner / an offline Defender scan if required), because some malicious extensions are accompanied by local components. If compromises are confirmed, report the malicious extension to the browser add‑on store (Chrome Web Store / Edge Add‑ons / Firefox Add‑ons) with the extension name, listing URL and timestamps so store staff can investigate. Consider changing passwords for other services that share the same credentials and enable MFA broadly. (support.microsoft.com)

Practical takeaway tied to this thread: the report from is the right signal—regularly audit installed extensions, limit permissions, keep browsers updated, and apply strong account hygiene on social platforms. These measures minimize the chance of falling for similar scams in future.

uisc 0 Newbie Poster

nice topic.....ilike your topic.

Muhammad Bashir 0 Newbie Poster

very good job

rjdoll77 -3 Newbie Poster

very nice article

HostBrink 0 Newbie Poster

Thanks for very useful information focusing tumblr users.... protected yourself from malware ....

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.