Malicious Google Chrome and Edge extensions downloaded more than 2 million times – here’s how to stay safe from being tracked online


- Koi Security researchers found almost two dozen browser add-ons spying on users
- The add-ons were tracking visited sites and communicating with remote C2 infrastructure
- Users were likely compromised along the way
Many Google Chrome and Microsoft Edge browser add-ons, including several prominent products, were found to be spying on users and communicating with a third-party server, in what appears to be a supply-chain attack with millions of victims.
Security researchers from Koi Security were recently looking into a seemingly benign Chrome add-on called “Color Picker, Eyedropper — Geco colorpick” which allows users to quickly identify and copy color codes from any point within their browser.
While working as advertised, and having thousands of downloads and positive reviews, the add-on also did something in the background – it hijacked browser activity, tracked the websites users were visiting, and communicated with remote C2 infrastructure. This prompted the researchers to investigate further, leading to the discovery of an entire web of add-ons, all doing similar things.
How to stay safe
They named the campaign Operation RedDirection, and counted 18 add-ons, cumulatively compromising 2.3 million users across Chrome and Edge.
The entire list of add-ons can be found here – it includes VPNs, site “unblockers”, weather forecast add-ons, emoji add-ons, and more.
The researchers also determined that these add-ons were not malicious from the get-go. They were simple, clean products that were most likely hijacked somewhere along the line. Many have hundreds of positive reviews, and some were featured in prominent places on the Chrome Web Store.
Most were removed from the Play Store, but according to BleepingComputer, “many of them continue to be available”. Although it wasn’t clearly specified, it’s safe to assume they’re available through third-party stores and standalone websites.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
If you were running any of the add-ons from the list, you should remove them immediately, clear browsing data, and run a full system scan using an updated antivirus solution.
It would also be wise to replace any passwords stored in the browser, as well as other sensitive auto-fill data. Data breaches are becoming increasingly common, with almost a third of enterprises experiencing a breach despite increased cybersecurity investments. You can see whether your information is affected using the popular breach checking website HaveIBeenPwned?
As well as identity theft protection software, users can keep themselves secure by being ultra cautious of any unexpected communications, thoroughly checking any emails and texts they receive, and never clicking on any untrusted links.
Via BleepingComputer
You might also like
Koi Security researchers found almost two dozen browser add-ons spying on users The add-ons were tracking visited sites and communicating with remote C2 infrastructure Users were likely compromised along the way Many Google Chrome and Microsoft Edge browser add-ons, including several prominent products, were found to be spying on users…
Recent Posts
- The Powerbeats Pro 2 are down to their best price yet for Prime Day
- NYT Wordle today — answer and my hints for game #1482, Thursday, July 10
- Sony’s Brand New Flagship Headphones Are on Sale for Prime Day
- Ceramic-based startup wants to put more than 100,000TB in a 42U rack by 2030 — but it will take almost 50 years to fill it up
- The 35 best Prime Day deals you can get for under $25
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022