Saturday, May 3, 2025
HomeChrome500+ Malicious Chrome Extensions Removed From the Official Chrome Web Store

500+ Malicious Chrome Extensions Removed From the Official Chrome Web Store

Published on

SIEM as a Service

Follow Us on Google News

Cybercriminals continue to host malicious chrome extensions in Google’s official Chrome Web Store to steal users’ data and redirect users to malicious websites.

Researchers observed a large malvertising campaign that presents a network of copycat plugins that shares a similar functionality.

These plugins initially appear to be legitimate, but they would infect users and exfiltrate sensitive user data.

- Advertisement - Google News

500+ Malicious Chrome Extensions

Security researcher Jamila Kaya used the free Cisco’s Duo Security tool CRXcavator uncovered this large malvertising campaign.

CRXcavator is a Chrome extension security check tool that analyzes the extension and provides the risks associated.

Malicious Chrome Extensions
CRXcavator

Before installing extensions, users can check with this tool by using the username or the extension ID and it shows the report.

Jamila and Duo worked together to detect dozens of extensions, they “utilize CRXcavator.io to identify 70 matching their patterns across 1.7 million users and escalate concerns to Google”.

Once installed the malicious extensions connect the “browser client to a command and control architecture, exfiltrate private browsing data without the user’s knowledge, expose the user to the risk of exploit through advertising streams, and attempt to evade the Chrome Web Store’s fraud detection mechanisms,” reads the report.

The primary malicious activity of the campaign is the ad fraud and they are achieved by redirecting the users to different websites.

A huge portion of the ads streams redirects to legitimate sites such as Macy’s, Dell, or Best Buy and other malicious websites.

Researchers believe that the threat actors are active for at least eight months, since January 2019, the activity grows rapidly.

These findings have been reported to Google, this allowed Google to search the entire Chrome store and remove more than 500 related extensions.

Here you can find the plugin name and the domains associated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hundreds of Fortune 500 Companies Have Unknowingly Employed North Korean IT Operatives

North Korean nationals have successfully infiltrated the employee ranks of major global corporations at...

Stealthy New NodeJS Backdoor Infects Users Through CAPTCHA Verifications

Security researchers have uncovered a sophisticated malware campaign utilizing fake CAPTCHA verification screens to...

State-Sponsored Hacktivism on the Rise, Transforming the Cyber Threat Landscape

Global cybersecurity landscape is undergoing a significant transformation, as state-sponsored hacktivism gains traction amid...

NVIDIA Riva AI Speech Flaw Let Hackers Gain Unauthorized Access to Abuse GPU Resources & API keys

Researchers have uncovered significant security vulnerabilities in NVIDIA Riva, a breakthrough AI speech technology...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hundreds of Fortune 500 Companies Have Unknowingly Employed North Korean IT Operatives

North Korean nationals have successfully infiltrated the employee ranks of major global corporations at...

State-Sponsored Hacktivism on the Rise, Transforming the Cyber Threat Landscape

Global cybersecurity landscape is undergoing a significant transformation, as state-sponsored hacktivism gains traction amid...

Stealthy New NodeJS Backdoor Infects Users Through CAPTCHA Verifications

Security researchers have uncovered a sophisticated malware campaign utilizing fake CAPTCHA verification screens to...