35 Google Chrome Extensions Hacked to Inject Malicious Code: What to Do

A massive phishing campaign compromised 35 popular Google Chrome extensions, affecting millions of users and extracting sensitive information. This blog provides an in-depth look at the attack, the affected extensions, and the steps you should take to protect yourself.

Jan 04, 2025 - 12:19
Updated: 8 days ago
108.5k
35 Google Chrome Extensions Hacked to Inject Malicious Code: What to Do

Quick answer: In a reported campaign, attackers phished the developers of Chrome extensions, took over their Web Store accounts and pushed malicious updates to about 35 extensions. Because Chrome updates extensions automatically, users received the code without doing anything. Protect yourself by removing unused extensions, restricting site access, reviewing permissions and, in organisations, allow-listing extensions.

Key takeaways

  • The attack targeted extension developers, then used the normal update channel to reach users.
  • An extension with permission to read all sites can see cookies, forms and session data.
  • Remove what you do not use, limit site access and review permissions regularly.
  • Organisations should allow-list extensions and monitor for permission changes.

What was reported

Security researchers reported a campaign in which attackers sent phishing emails to Chrome extension developers, posing as Chrome Web Store support. The emails pushed developers to authorise a malicious application through an OAuth consent screen. With that access, attackers could publish new versions of the developers' extensions. Reports named about 35 extensions and a combined user count of around 2.6 million. These figures come from researcher and press reports, so check the primary write-ups before quoting them. The aim was to steal data such as session information and credentials, with particular interest in advertising accounts on social media.

The older version of this article gave a specific date for the incident. That date does not match the reporting I know of, so it has been removed. Confirm timing against the original researchers' publications.

Why this works: the supply-chain problem

You trusted the extension, and the extension was updated by someone who was not its author. That is a supply-chain attack. Chrome extensions update silently, so a clean extension can become malicious overnight. Nothing was wrong with your browser or your habits. The weak point was the developer's account.

An extension that can "read and change all your data on all websites" can see what you type, read page content and steal cookies for logged-in sessions. That is why permissions matter more than the extension's reputation.

Audit your extensions in ten minutes

  1. Open chrome://extensions in Chrome.
  2. For each extension, ask: do I use this weekly? If not, remove it.
  3. Click Details. Under Site access, change broad "On all sites" to On click or On specific sites wherever possible.
  4. Read the permissions list. A colour picker should not need access to every site.
  5. Check the developer name, the Web Store listing, recent reviews and the last update date. Sudden changes of owner or permissions are a warning.
  6. Use a separate browser profile for banking and admin work, with almost no extensions.
  7. Keep Chrome updated and enable Safe Browsing.

If you ran an extension named in a credible incident report, remove it, sign out of sensitive accounts, change passwords from a clean device, revoke active sessions and enable MFA. If money or accounts were affected in India, report at cybercrime.gov.in.

For organisations

  • Allow-list extensions using Chrome enterprise policies, and block everything else.
  • Review permissions before approving, and re-review after updates that add permissions.
  • Inventory installed extensions on managed devices.
  • Protect extension developer accounts if you publish extensions: phishing-resistant MFA, careful review of OAuth consent requests and a separate account for publishing.
  • Monitor for unusual outbound traffic from browsers to unknown domains.

For developers

Treat any email about your store listing as suspicious. Go to the Chrome Web Store dashboard directly, never through a link. Review which third-party apps have access to your Google account. Use a security key.

The same risk elsewhere

Code editor and browser add-ons share this risk. See Firefox extensions that steal crypto wallets and malicious VS Code extensions.

Next steps

Understanding supply-chain and web-session risks is a core security skill. The Cyber Security course covers it, and the OWASP Top 10 lists the web risks behind session theft.

Related reading

Frequently Asked Questions

Attackers reportedly phished extension developers, gained control of their Web Store accounts and published malicious updates to about 35 extensions. The code aimed to steal session data and credentials.

Open chrome://extensions, review every extension, remove ones you do not use and compare the rest with credible incident reports. If you ran an affected one, change passwords and revoke sessions.

Chrome updates extensions automatically so users get fixes quickly without any action. The same update channel can deliver malicious code to every user if an attacker takes over the developer's account.

In the extension's details, set Site access to On click or specific sites, remove extensions you do not need and use a separate browser profile for banking and admin work.

Use Chrome enterprise policies to allow-list approved extensions, review permissions after updates, keep an inventory of installed extensions and monitor unusual outbound traffic from browsers.

Not always. Attackers in this campaign reportedly used OAuth consent phishing, which can bypass MFA prompts. Use phishing-resistant keys, review third-party app access and never approve consent from an email link.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.