• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Project of the Week
  • About Us
    SEARCH
Network Security, News

Malicious Browser Extensions Downloaded More Than 3 Million Times, Cybersecurity Firm Says

According to cybersecurity researchers, 28 browser extensions on Microsoft Edge and Google Chrome contain malicious code that compromises devices.

December 17, 2020 Zachary Comeau Leave a Comment

Malicious Browser Extensions

According to cybersecurity researchers, 28 browser extensions on Microsoft Edge and Google Chrome contain malware, and they’ve been downloaded by more than three million people.

In a blog post, cybersecurity firm Avast said it has analyzed 28 malicious browser extensions after a group of Czech researchers identified the threat and found extensions to contain malware. They include things like Video Downloader for Facebook, Vimeo Video Downloader, Instagram Story Downloader, VK Unblock and other browser extensions.

According to Avast, browser store download figures indicate more than three million users could be affected worldwide. The firm started monitoring this threat in November 2020, but this attack method could have been active for years without being detected.

Avast has reported this to Microsoft and Google, and the firms are investigating, according to Avast.

The firms’ blog notes that reviews on the Chrome Web Store mention link hijacking from December 2018, meaning malicious browser extensions could have been infecting uses’ devices for nearly two years.

According to Avast, the firm believes that the extensions were either deliberately created with malware built in, or the author waited for the extensions to become popular and then published an update containing the malware. Or, the author could have sold the original extensions to someone else after creating them who could have introduced the malware afterwards.

Read Next: What We Know About The Massive Hack of SolarWinds’ IT Management Platform

Malicious code in the infected JavaScript-based browser extensions also allow for even more malware to be downloaded to a device. The code also manipulates links that victims click on after downloading the extensions, exposing users to phishing sites and ads.

Avast believes the owners of the domains pay the cyber actors for every redirection rather than the cyber actors actually owning the domains themselves.

When users click on the links, the extensions send information to the attacker’s control server, creating a log of all clicks that is sent to third-party websites that can be used to collect personal information about users.

That information includes birth date, email addresses, device information, login times, names of devices, operating system, browser used and IP addresses.

On Thursday morning, the extensions were still available for download. Users who think they have downloaded one should disable and uninstall them immediately, then scan for and remove malware.

At the time of publishing, the infected extensions are still available for download. If you suspect you might have downloaded one, Avast researchers recommend disabling and uninstalling them immediately and then scan for and remove malware. They have also reported the issue to Microsoft and Google, who are looking into it.

If you enjoyed this article and want to receive more valuable industry content like this, click here to sign up for our digital newsletters!

Tagged With: Avast, Browser, Cybersecurity, Google Chrome, Microsoft Edge

Related Content:

  • Cloud, SASE, Aryaka How the Cloud is Redefining Media Production and…
  • Singlewire Software mass notification interview Singlewire Software on Mass Notification Solutions
  • URI catchbox 1 Catchbox Plus: The Mic Solution That Finally Gave…
  • Engaging virtual meeting with diverse participants discussing creative ideas in a bright office space during daylight hours Diversified Survey: Workplace AV Tech is Falling Short,…

Free downloadable guide you may like:

  • Download TechDecisions' Blueprint Series report on Security Awareness now!Blueprint Series: Why Your Security Awareness Program is Probably Falling Short

    Learn about the evolution of phishing attacks and best practices for security awareness programs to ensure your organization is properly prepared to defend against them in this report from TechDecisions' Blueprint Series.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest Downloads

Practical Design Guide for Office Spaces
Practical Design Guide for Office Spaces

Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-fa...

New Camera Can Transform Your Live Production Workflow
New Camera System Can Transform Your Live Production Workflow

Sony's HXC-FZ90 studio camera system combines flexibility and exceptional image quality with entry-level pricing.

Creating Great User Experience and Ultimate Flexibility with Clickshare

Working and collaborating in any office environment today should be meaningful, as workers today go to office for very specific reasons. When desig...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Contact Us
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSYour Privacy ChoicesTERMS OF USEPRIVACY POLICY

© 2025 Emerald X, LLC. All rights reserved.