Google’s malicious extension problem exposes store verification failure

Kavitha Nair
By
Kavitha Nair
Tech writer at All Things Geek. Covers the business and industry of technology.
8 Min Read
Google's malicious extension problem exposes store verification failure

Malicious Chrome extensions represent one of the most damaging failures of Google’s Web Store verification system in recent years. Researchers at Koi Security uncovered 18 malicious extensions across Chrome and Edge that infected over 2.3 million users, with Google actively promoting several through verification badges and featured placement even after Microsoft had already banned them from Edge. The campaign operated for years—in some cases spanning seven years—with one extension remaining promoted by Google for over a year after Microsoft removed it.

Key Takeaways

  • 18 malicious extensions infected 2.3 million users across Chrome and Edge browsers.
  • Extensions used “sleeper agent” tactics: clean versions built trust for years before malicious updates added spyware.
  • Google gave verification badges and featured placement to extensions Microsoft had already banned.
  • Malware captured URLs, tracked users with unique IDs, and auto-redirected browsers to attacker-controlled sites.
  • All reported extensions were removed after Koi Security’s disclosure, but persistent installs continue tracking users.

How the Sleeper Agent Attack Worked

The malicious Chrome extensions employed a sophisticated long-game strategy. Developers released clean, legitimate-looking extensions years earlier—some dating back to 2018—that accumulated millions of genuine installs and positive user reviews. This trust foundation was critical. Once the extensions had built credibility, attackers pushed malicious updates through automatic update systems that users never explicitly approved. The updates silently added spyware without notification or user consent.

The malware’s behavior was systematic and invasive. When users visited websites, the extensions captured the URLs they were browsing and sent them to a remote command-and-control server alongside a unique tracking identifier. The C2 server then returned redirect instructions, causing the browser to automatically navigate to attacker-controlled pages. Beyond URL hijacking, the extensions also logged browsing history, search queries, mouse clicks, browser fingerprints, and HTTP referrers—a comprehensive surveillance toolkit. Chrome saw approximately 1.7 million installs of affected extensions, while Edge hosted around 600,000.

Specific extensions included Emoji Keyboard Online, Free Weather Forecast, Unlock Discord, Dark Theme, Volume Max, and others. One particularly troubling example came from publisher Starlab Technology, whose extensions reached over 3 million installs before removal. This scale meant millions of users unknowingly transmitted their browsing behavior to criminals.

Why Google’s Verification Failed While Microsoft Acted

Microsoft Edge removed several of these malicious extensions from its store, but Google’s Web Store continued promoting them with verification badges and featured placements. This divergence exposes a critical gap in Google’s review process. According to Koi Security researcher Idan Dardikman, “Google’s and Microsoft’s verification process failed to detect sophisticated malware across eleven different extensions, instead promoting several to users through verification badges and featured placement”. The verification badge—meant to signal trust—became a liability, lending false credibility to malicious code.

The timing reveals another problem. Google kept promoting at least one extension for over a year after Microsoft had already identified and banned it. This suggests Google’s store reviewers either did not communicate with Microsoft’s security team or lacked the sophistication to detect what Microsoft’s analysts had flagged. The extensions persisted in Chrome’s ecosystem long after the threat was known to the industry.

Dardikman added that the campaign “perfectly demonstrates how sophisticated threat actors are exploiting the trust signals we rely on”. Verification badges, featured placement, and high install counts all become weapons when verification systems fail. Users reasonably assume that extensions recommended by Google have undergone rigorous security review. That assumption proved dangerously wrong.

What Users Should Do Now

Even after Google removed the malicious extensions from the Web Store in July 2025, the threat persisted for users who had already installed them. Installed extensions continue functioning and syncing data across devices through Chrome’s sync system. Koi Security recommended a comprehensive remediation process.

First, users should immediately remove all listed malicious extensions from their Chrome and Edge browsers. Second, they should clear all browser data to purge stored tracking identifiers, including the unique UUIDs stored in chrome.storage.sync that attackers used for tracking. Third, run a full system malware scan to detect any additional compromises. Fourth, update the browser to apply the latest security patches and blocklists. Finally, monitor sensitive accounts—especially banking, email, and social media—for suspicious activity, since attackers had captured browsing history and search queries.

Why This Matters Beyond This Single Campaign

This incident exposes a structural vulnerability in how browser extension stores operate. Extensions have deep access to browsing behavior, passwords, and personal data. Unlike app stores that distribute sandboxed applications, browser extensions are essentially mini-programs with near-total visibility into user activity. When verification fails at scale—affecting 2.3 million users—the damage is immediate and invasive.

The sleeper agent tactic also suggests that attackers are thinking in longer timelines than security teams. By releasing clean extensions years before activation, they bypass reputation systems and accumulate the install counts that make extensions appear trustworthy. A new extension with 100,000 installs in a week might trigger scrutiny. An old extension with 3 million installs accumulated over five years feels safe. This patience-based attack vector is difficult to detect without behavioral analysis of update patterns—something Google’s automated review apparently did not perform.

Is Google’s store verification improving?

Google removed the reported extensions after Koi Security’s disclosure, but the company has not publicly committed to preventing similar campaigns. The verification badge system remains in place without announced changes to detection methods. Microsoft also removed affected extensions from Edge, but both companies’ responses came only after external researchers did the work.

What makes these extensions different from typical adware?

Unlike traditional adware that displays banners, these extensions operated invisibly. They captured and transmitted browsing data to attackers without any visible indication to users. One developer described similar hijacked extensions as “invisible ads that work in the background and replace links on every website that you visit into affiliate links”. The surveillance component—tracking every page visited and sending that data to a remote server—made this campaign far more invasive than standard ad injection.

How long will these extensions keep tracking users?

Extensions already installed will continue functioning until manually removed, even though Google deleted them from the Web Store. The sync data containing tracking UUIDs persists across devices, meaning attackers can still correlate a user’s browsing across multiple machines. Users must actively uninstall and clear data—the threat does not automatically stop.

The malicious Chrome extensions campaign reveals that Google’s Web Store verification system cannot reliably detect sophisticated threats, even when competitors have already flagged them. For millions of users who installed these extensions in good faith, the damage is already done. The real question is whether Google will fundamentally rethink how it reviews extensions before trust is broken further.

Edited by the All Things Geek team.

Source: Windows Central

Share This Article
Tech writer at All Things Geek. Covers the business and industry of technology.