Malicious Google Chrome and Edge extensions downloaded more than 2 million times – here’s how to stay safe from being tracked online
- Koi Security researchers found almost two dozen browser add-ons spying on users
- The add-ons were tracking visited sites and communicating with remote C2 infrastructure
- Users were likely compromised along the way
Many Google Chrome and Microsoft Edge browser add-ons, including several prominent products, were found to be spying on users and communicating with a third-party server, in what appears to be a supply-chain attack with millions of victims.
Security researchers from Koi Security were recently looking into a seemingly benign Chrome add-on called “Color Picker, Eyedropper — Geco colorpick” which allows users to quickly identify and copy color codes from any point within their browser.
While working as advertised, and having thousands of downloads and positive reviews, the add-on also did something in the background – it hijacked browser activity, tracked the websites users were visiting, and communicated with remote C2 infrastructure. This prompted the researchers to investigate further, leading to the discovery of an entire web of add-ons, all doing similar things.
How to stay safe
They named the campaign Operation RedDirection, and counted 18 add-ons, cumulatively compromising 2.3 million users across Chrome and Edge.
The entire list of add-ons can be found here – it includes VPNs, site “unblockers”, weather forecast add-ons, emoji add-ons, and more.
The researchers also determined that these add-ons were not malicious from the get-go. They were simple, clean products that were most likely hijacked somewhere along the line. Many have hundreds of positive reviews, and some were featured in prominent places on the Chrome Web Store.
Most were removed from the Play Store, but according to BleepingComputer, “many of them continue to be available”. Although it wasn’t clearly specified, it’s safe to assume they’re available through third-party stores and standalone websites.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
If you were running any of the add-ons from the list, you should remove them immediately, clear browsing data, and run a full system scan using an updated antivirus solution.
It would also be wise to replace any passwords stored in the browser, as well as other sensitive auto-fill data. Data breaches are becoming increasingly common, with almost a third of enterprises experiencing a breach despite increased cybersecurity investments. You can see whether your information is affected using the popular breach checking website HaveIBeenPwned?
As well as identity theft protection software, users can keep themselves secure by being ultra cautious of any unexpected communications, thoroughly checking any emails and texts they receive, and never clicking on any untrusted links.
Via BleepingComputer
You might also like
Koi Security researchers found almost two dozen browser add-ons spying on users The add-ons were tracking visited sites and communicating with remote C2 infrastructure Users were likely compromised along the way Many Google Chrome and Microsoft Edge browser add-ons, including several prominent products, were found to be spying on users…
Recent Posts
- Canada Prime Minister Mark Carney announces questionable national AI strategy
- Kevin O’Leary agrees to downsize massive Utah data center
- This HP Omen 16 deal with RTX 5050 graphics is a steal for video editing — and I can’t find it cheaper anywhere else
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
- How to watch France vs Ivory Coast: FREE streams, TV channels for World Cup 2026 warm-up
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023