Millions face privacy breach after malicious browser extensions spread

If you’re like most of us, you probably rely on your web browser for everything these days—catching up on news, checking your bank balance, chatting with the grandkids, and maybe even a cheeky bit of online shopping.

But what if we told you that something as simple as a browser extension could be quietly spying on you, tracking your every move, and even putting your personal information at risk?


That’s exactly what’s happened to millions of people around the world, including right here in Australia, thanks to a recent discovery by cybersecurity researchers.

They’ve uncovered a sneaky campaign involving 18 browser extensions—available through the official Chrome and Edge web stores—secretly tracking users’ online behaviour.

The total number of installs? Over two million. Yikes!


1752201891803.png
Over two million users get spied on by 18 malicious Chrome and Edge extensions that track activity and hijack sessions. Credit: Depositphotos


These weren’t dodgy downloads from the dark corners of the internet.

These extensions looked perfectly legitimate, offering handy features like weather updates, emoji keyboards, and even dark mode for your browser.

They had glowing reviews, shiny verification badges, and the web stores themselves even featured some.


But here’s the catch: cybercriminals have figured out a clever trick. They start by releasing a clean, innocent extension—what some experts call a 'sleeper agent.'

It works as advertised, builds up a good reputation, and then, after months or even years, the bad guys push out an update that quietly adds malicious code.

Suddenly, your trusty extension is up to no good.

Once 'activated,' these extensions would spring into action every time you visited a new website. Here’s what they did:
  • Captured the URL of every page you visited.
  • Sent that information, along with a unique ID to track you, to a remote server.
  • Waited for instructions from the cybercriminals’ command centre.
  • If told to do so, redirected you to a different website—sometimes a fake version of a real site.
Imagine this: you get a Zoom meeting invite, click the link, and instead of joining your meeting, you’re whisked away to a convincing fake page telling you to download a 'critical Zoom update.'

You download it, thinking you’re being safe, but you’ve just installed even more malware. Suddenly, your device—and all your info—could be completely compromised.


Most of the malicious extensions have now been removed from the webstores, but if you installed one before it was taken down, you could still be at risk.

And while we always recommend sticking to official webstores for your downloads, this incident proves that even 'safe' sources aren’t foolproof.

First, check your browser for these extensions. Here’s the list of the main offenders:

Chrome Extensions:
  • Emoji keyboard online
  • Free Weather Forecast
  • Unlock Discord
  • Dark Theme
  • Volume Max
  • Unblock TikTok
  • Unlock YouTube VPN
  • Geco colorpick
  • Weather
Edge Extensions:
  • Unlock TikTok
  • Volume Booster
  • Web Sound Equalizer
  • Header Value
  • Flash Player
  • Youtube Unblocked
  • SearchGPT
  • Unlock Discord
If an extension suddenly asks for new permissions after an update—especially ones that don’t make sense for what it’s supposed to do—be suspicious.

It’s always better to be safe than sorry. This incident is a timely reminder that even the most tech-savvy among us can fall victim to online scams.
Key Takeaways
  • More than two million users were spied on by 18 malicious Chrome and Edge browser extensions that secretly tracked browsing activity and could hijack web sessions.
  • Many of the suspicious extensions appeared trustworthy, with good reviews and verification badges, but later received updates containing hidden malware, effectively turning them into 'sleeper agents'.
  • Affected users risked being redirected to fake sites, where they might unknowingly download further malware, potentially leading to full device compromise.
  • Users are urged to check for specific dangerous extensions, remove them, clear browser data, monitor accounts, enable two-factor authentication, update software, and run antivirus scans for protection.
Have you ever had a dodgy extension sneak onto your computer? Or maybe you’ve got a tip for staying safe online? Share your stories and advice in the comments below—let’s help each other stay one step ahead of the cyber crooks!

Read more: Web browser users face urgent security risk as millions warned to remove dangerous extensions
 

Seniors Discount Club

Sponsored content

Info
Loading data . . .
A few months ago, I installed a weather app on my laptop through Google Chrome. When completed, I copped a barrage of "anti virus" pop-ups telling me "582 viruses have been found on your device" and the like. It basically froze my operating system.

After some complex deep cleansing of my device, it was back to normal.

I do not have any purchased anti virus, malware, trojan, ransomware or phishing software on my laptop. They are a waste of money but I am nowhere a computer "expert". I just know how to find the right tools in such a situation.
 

Join the conversation

News, deals, games, and bargains for Aussies over 60. From everyday expenses like groceries and eating out, to electronics, fashion and travel, the club is all about helping you make your money go further.

Seniors Discount Club

The SDC searches for the best deals, discounts, and bargains for Aussies over 60. From everyday expenses like groceries and eating out, to electronics, fashion and travel, the club is all about helping you make your money go further.
  1. New members
  2. Jokes & fun
  3. Photography
  4. Nostalgia / Yesterday's Australia
  5. Food and Lifestyle
  6. Money Saving Hacks
  7. Offtopic / Everything else
  • We believe that retirement should be a time to relax and enjoy life, not worry about money. That's why we're here to help our members make the most of their retirement years. If you're over 60 and looking for ways to save money, connect with others, and have a laugh, we’d love to have you aboard.
  • Advertise with us

User Menu

Enjoyed Reading our Story?

  • Share this forum to your loved ones.
Change Weather Postcode×
Change Petrol Postcode×