Recently, security firm Avast recently reported that more than 3 million users have installed 28 dangerous extensions. Of these, there are 15 extensions for Google Chrome and 13 extensions for Microsoft Edge.
According to Avast, these 28 extensions contain code that executes some harmful behaviors such as:
The main purpose of these extensions, according to Avast. is monetization by redirecting user traffic to other sites. These pages are mainly advertising and phishing sites. They will pay extension developers based on the traffic generated by the extension.
Avast discovered these extensions last month, but there is some evidence that they exist since December 2018. At that time, some users realized that they were sometimes redirected to unfamiliar sites.
Jan Rubín, an expert on malware at Avast, said that it is not possible to determine whether these extensions contained malicious code in the first place or was recently added via the updated channel. Many of these extensions have attracted a lot of downloads.
Avast has reported the issue to both Microsoft and Google and the two companies are working on investigations and verification. Currently both Microsoft and Google have not commented yet.
Here is a list of malicious extensions on Google Chrome:
And on Microsoft Edge:
Avast recommends that users remove these extensions early to ensure their safety.
ncG1vNJzZmismaXArq3KnmWcp51kf3l5w5qloJ2ipMK0ecSxq56mo568r7%2BMsqauZaOdvLa4w2agpqWVmbaiwMSlsGaqlaK8t7GMn6mopV2YtbO7zJ5kmqaUYrqqr9GoqqiepGKypbPE