Malicious Google Chrome and Edge extensions downloaded more than 2 million times – here’s how to stay safe from being tracked online


- Koi Security researchers found almost two dozen browser add-ons spying on users
- The add-ons were tracking visited sites and communicating with remote C2 infrastructure
- Users were likely compromised along the way
Many Google Chrome and Microsoft Edge browser add-ons, including several prominent products, were found to be spying on users and communicating with a third-party server, in what appears to be a supply-chain attack with millions of victims.
Security researchers from Koi Security were recently looking into a seemingly benign Chrome add-on called “Color Picker, Eyedropper — Geco colorpick” which allows users to quickly identify and copy color codes from any point within their browser.
While working as advertised, and having thousands of downloads and positive reviews, the add-on also did something in the background – it hijacked browser activity, tracked the websites users were visiting, and communicated with remote C2 infrastructure. This prompted the researchers to investigate further, leading to the discovery of an entire web of add-ons, all doing similar things.
How to stay safe
They named the campaign Operation RedDirection, and counted 18 add-ons, cumulatively compromising 2.3 million users across Chrome and Edge.
The entire list of add-ons can be found here – it includes VPNs, site “unblockers”, weather forecast add-ons, emoji add-ons, and more.
The researchers also determined that these add-ons were not malicious from the get-go. They were simple, clean products that were most likely hijacked somewhere along the line. Many have hundreds of positive reviews, and some were featured in prominent places on the Chrome Web Store.
Most were removed from the Play Store, but according to BleepingComputer, “many of them continue to be available”. Although it wasn’t clearly specified, it’s safe to assume they’re available through third-party stores and standalone websites.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
If you were running any of the add-ons from the list, you should remove them immediately, clear browsing data, and run a full system scan using an updated antivirus solution.
It would also be wise to replace any passwords stored in the browser, as well as other sensitive auto-fill data. Data breaches are becoming increasingly common, with almost a third of enterprises experiencing a breach despite increased cybersecurity investments. You can see whether your information is affected using the popular breach checking website HaveIBeenPwned?
As well as identity theft protection software, users can keep themselves secure by being ultra cautious of any unexpected communications, thoroughly checking any emails and texts they receive, and never clicking on any untrusted links.
Via BleepingComputer
You might also like
Koi Security researchers found almost two dozen browser add-ons spying on users The add-ons were tracking visited sites and communicating with remote C2 infrastructure Users were likely compromised along the way Many Google Chrome and Microsoft Edge browser add-ons, including several prominent products, were found to be spying on users…
Recent Posts
- Not Just Any Prime Day Deals, 220 Obsessively Tested Picks—even $1,200 off an OLED TV
- Samsung Galaxy Unpacked 2025 as it happened – the new Z Fold 7, Z Flip 7 and Galaxy Watch 8 are here
- The Bezos-funded climate satellite is lost in space
- Samsung’s big folding phone redesign is a breath of fresh air in a sea of AI-first phone launches
- The best 4K TV deals during Prime Day 2025
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022