Google Purges Over 500 Malicious Chrome Extensions from Web Store

Google removes more than 500 Chrome extensions after security researchers discover they secretly redirect users to malicious ads. Millions of users are likely impacted by the hidden malware.

Google removes over 500 Chrome extensions from its Web Store after security researchers at Cisco's Duo discover that the tools secretly redirect users to malicious sites and ad content. The developers behind these extensions hide their true advertising functionality to connect browsers to a command and control architecture, exfiltrate private browsing data without the users' knowledge, and attempt to evade Google's fraud detection systems.

Millions of users experience the impact of this mass removal. Duo's initial investigation reveals that almost two million users download the specifically identified extensions, but Google's subsequent cleanup action significantly expands this scope. Most impacted users report being completely unaware of any obvious changes to their browsing experience, as the malicious redirects happen silently in the background to generate illegitimate ad revenue for the creators.

This type of browser extension fraud is unfortunately not a new occurrence for Google. Similar attacks in the past involve injecting hidden ads into browsing sessions, while more severe incidents in 2018 see groups using Chrome extensions to steal login credentials, mine cryptocurrencies, and engage in click fraud. Because of these persistent threats, it is essential for users to ensure their installed extensions come from reputable sources and to avoid suspicious or spammy-looking listings.

Read More at the original source →