Google Removes Over 500 Malicious Chrome Extensions Exposing Millions
Google removes more than 500 data-stealing Chrome extensions from its Web Store after a security researcher uncovers a massive ad fraud network.
Google removes over 500 malicious Chrome extensions from its Web Store after a security researcher uncovers a massive network stealing user data and executing ad fraud. These deceptive extensions infect millions of computers before their removal, highlighting how easily malicious software evades Google's initial screening processes.
Researcher Jamila Kaya uses Duo Security's CRXcavator tool to identify the initial group of suspicious extensions, which mostly disguise themselves as marketing and advertising tools. She discovers that the malicious code acts as copycats with only minor changes to internal function names, and the extensions request excessive permissions to access sensitive browsing data even on secure HTTPS websites.
The identified extensions actively engage in click fraud by secretly contacting command and control domains, while also redirecting unsuspecting users to malware and phishing sites. Many of these threats remain active for nearly a year, prompting Google to expand the researcher's initial findings of 70 extensions into a much larger sweep of over 500 violating applications.