Google Purges 500 Malicious Chrome Extensions After Security Research
Google removes 500 deceptive Chrome extensions from its Web Store that bombard users with unwanted ads and malicious redirects. The malicious add-ons affect over 1.7 million users before researchers alert the tech giant.
Google removes 500 malicious Chrome extensions from its Web Store following an investigation triggered by security researcher Jamila Kaya from Cisco's Duo Security. These deceptive add-ons copy legitimate tools to trick users while secretly bombarding them with advertisements. The researcher discovers the malicious network using the CRXcavator tool, which analyzes Chrome extensions for potential threats.
The malicious extensions collectively affect over 1.7 million users by injecting scripts into their browsing sessions. These scripts redirect users to various websites, with most links pointing to malicious domains, though some lead to legitimate retailers like BestBuy and Macy's. Initially, Kaya identifies only a few dozen of these add-ons before realizing a much larger coordinated network exists.
After Duo Security shares its findings with Google, the tech giant launches a thorough investigation that uncovers the full scope of the operation. Google promptly removes all 500 associated extensions from the Web Store and states that it uses such incidents to improve its automated and manual analysis systems. Although the threat is eliminated, security researchers still advise users to remain vigilant when installing browser add-ons.