Yikes! Google just removed more than 500 malicious Chrome extensions

Chrome browser on desktop displaying Chrome logo.
(Image credit: Footage Vector Photo/Shutterstock)

Google pulled over 500 malicious Chrome extensions from the Web Store after security researchers exposed a malware operation that injects nasty ads in users’ browsing sessions.

Cisco’s Duo Security team, which shared its report with ZDNet, found malicious code that is activated under specific conditions and redirects users while browsing. The destinations varied from affiliate links for retail sites like Dell or BestBuy to malware download or phishing pages.

According to the report, the malware-injecting extensions are tied to a larger effort that’s been operating for at least two years. It’s believed the bad actors behind the code may have been active since the early 2010s. 

Exposed by a free tool

Security researcher Jamila Kaya told ZDNet that she discovered the network of malicious extensions during routine threat hunting using Duo's free CRXcavator tool, which analyzes the security of Chrome plug-ins. She noticed a common URL pattern among redirected sites.

"Individually, I identified more than a dozen extensions that shared a pattern," Kaya told ZDNet. "Upon contacting Duo, we were able to quickly fingerprint them using CRXcavator's database and discover the entire network."

Duo believes 1.7 million users had installed the initial extensions Kaya identified. Google flagged hundreds more malicious extensions in its own security sweep, though. It’s unknown how many installations those 500-plus plug-ins had.

Duo’s report serves as a reminder that Google has ongoing malware issues. Chrome extension security problems arise with alarming regularity. While the company has made efforts to beef up restrictions on extensions, there’s still a cause for concern.

Chrome malware: What you can do

Google has removed over 500 malicious extensions from the web store and also deactivated them within users’ browsers. If you have one of the bad extensions installed on your own browser, Google has labeled it as "malicious,” so you know to delete it and not reactivate it.

Duo published an index of the malicious extensions if you’re still not sure whether you have one or more of them installed in your browser.

The security firm also recommends you regularly audit the extensions you have installed, delete ones you don’t use and flag ones you don’t recognize. Some of the best antivirus programs will also detect and defang malicious browser extension.

TOPICS
Kate Kozuch

Kate Kozuch is the managing editor of social and video at Tom’s Guide. She writes about smartwatches, TVs, audio devices, and some cooking appliances, too. Kate appears on Fox News to talk tech trends and runs the Tom's Guide TikTok account, which you should be following if you don't already. When she’s not filming tech videos, you can find her taking up a new sport, mastering the NYT Crossword or channeling her inner celebrity chef.

Read more
and image of the Google Chrome logo on a laptop
Popular Chrome extensions hijacked by hackers in widespread cyberattack — 3.2 million at risk
and image of the Google Chrome logo on a laptop
Over 600,000 Chrome users at risk after 16 browser extensions compromised by hackers — what you need to know
and image of the Google Chrome logo on a laptop
Google Chrome at risk from shape-shifting browser extensions — how to stay safe
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
and image of the Google Chrome logo on a laptop
Billions of Chrome users at risk from new browser-hijacking Syncjacking attack — how to stay safe
Latest in Browsers
iPhone 16 Pro Max shown in hand
Your iPhone has a custom voice command feature — here's how to use it
iPhone 16 Pro Max shown in hand
You can change your iPhone's default browser — here's how
Google Chrome on Android
How to stop your personal data from appearing in Google searches
Opera Air
I just tested the world’s first mindful browser — it’s calmly convinced me to ditch Google Chrome
A photo of the Google Chrome logo on a white background, displayed on the screen of a large MacBook Pro which is situated on a table with green foliage behind.
Google Chrome just got three new modes — and it's a game changer for performance
Google Calendar app on iPhone
Google Calendar just got the dark mode we’ve been waiting for — here’s how to activate it
Latest in News
Tom Hiddleston as Robert Laing in "High Rise" now streaming on Netflix
5 best Netflix movies in March you haven't watched yet
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features
Wolfenstein: The Old Blood
Amazon is giving away a ton of free games for its Big Spring Sale — here’s how to claim yours
A TV with the Netflix logo sits behind a hand holding a remote
Netflix is rolling out a big video quality upgrade — what you need to know