Millions of us are using malicious browser extensions without realizing

Hands typing on a keyboard surrounded by security icons
(Image credit: Shutterstock)

Malicious browser extensions are becoming so widespread that millions of users apparently have them installed.

A new report from Kaspersky analyzing telemetry data from its endpoint protection solution and found that in the last two and a half years (between January 2020 and June 2022), there had been more than 4.3 million unique users attacked by adware hiding in browser extensions. In other words, some 70% of all affected users encountered this type of threat.

Furthermore, it claims to have prevented more than six million users from downloading malware, adware, and riskware disguised as browser extensions, in that time period.

Adware and malware

These extensions target users with adware and other forms of malware on a daily basis, while they remain oblivious to the fact that they’re actually being attacked.

The most popular type of malicious browser extension is adware - unwanted software that promotes affiliates rather than improves the user experience. These extensions monitor user behavior through browser history, in order to redirect them to affiliate pages and thus earn commission for their makers. According to Kaspersky, WebSearch is the biggest in this category, detected by antivirus programs as not-a-virus:HEUR:AdWare.Script.WebSearch.gen, and downloaded almost 900,000 times. 

While this tool promises to improve the experience of office workers (by simplifying conversion between .doc and .pdf files, for example), it actually changes the browser’s start page, and uses the resources to earn extra money through affiliate links. 

The extension also changes the browser’s default search engine to myway, which captures user queries, collects, analyzes them, and then serves the victim affiliate links in search engine results pages.

The second most popular type is malware, usually built to steal login credentials and other sensitive information, such as payment data. 

The best way to protect your devices from malicious browser plugins is to make sure to always download them from trusted sources, and to check reviews and ratings.

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
chrome firefox extensions
Google Chrome extensions hit in major attack - dozens of developers affected, so be on your guard
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
Chrome icon on Android
Google Chrome extensions hack may have started much earlier than expected
A padlock resting on a keyboard.
Understanding and avoiding malvertizing attacks
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Microsoft reveals over a million PCs hit by malvertising campaign
Latest in Security
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Image depicting a hand on a scanner
Hackers are targeting unpatched ServiceNow instances that exploit 3 separate year-old vulnerabilities
Latest in News
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models
Seth Milchick and Kier Eagan's animatronic speaking in Severance season 2 episode 10
Apple TV+ announces Severance has been renewed for season 3 after that devastating finale
AMD Ryzen AI
New leak suggests AMD's working on an Arm-based processor to rival Qualcomm's Snapdragon X series
Apple's Craig Federighi presenting customization options in iOS 18 at the Worldwide Developers Conference (WWDC) 2024.
iOS 19: new features, a new design, and everything you need to know