Malware-filled extensions are a Chrome threat you can’t ignore — reportedly installed by 280 million

In the same way that you need to be careful when installing new apps on your smartphone, you also have to be cautious when adding new extensions to your browser, especially with Google Chrome.

With a 65% market share worldwide according to Statcounter, Chrome is the most popular browser by far which makes it the perfect target for hackers and other cybercriminals. While cyberattacks often exploit zero-day flaws in Google’s browser, there’s an easier way to target Chrome users: malicious extensions.

Just like with malicious apps, these bad extensions can contain malware and other threats designed to steal your data as well as your cash. Of the 250,00 extensions on the Chrome Web Store, less than 1% were found to include malware according to a recent blog post from Google. However, a new research paper is claiming differently.

Published by researchers from Stanford University and the CISPA Helmholtz Center for Information Security, the research paper (PDF) claims that 280 million people installed a malware-infected Chrome extension between July 2020 and February 2023.

Here’s everything you need to know about malicious Chrome extensions and how you can stay safe when adding new extensions to your browser.

Lasting threats

As reported by TechSpot, the researchers found that over a three year period, 346 million users installed Security-Noteworthy Extensions (SNE). While 63 million of these extensions were policy violations and 3 million were vulnerable, 280 million of these installs actually contained malware.

Surprisingly, many of these malicious extensions were available to download on the Chrome Web Store for quite some time. The malware-filled ones remained on the store for 380 days on average while the ones with vulnerable code stayed up for 1,248 days on average.

Of these malicious extensions, one called TeleApp was available to download and install for 8.5 years. The extension itself was updated in 2013 before it was finally removed after it was found to contain malware in 2022.

Normally with apps on the Google Play Store, I recommend checking user ratings and reviews to see if they are malicious. However, the researchers found that this doesn’t help when it comes to bad extensions as many of them don’t have any reviews at all. This could indicate that their users don’t know they’re dangerous or that they just didn’t take the time to rate and review them.

How to stay safe from malicious extensions

malware-filled extensions are a chrome threat you can’t ignore — reportedly installed by 280 million

((Image credit: Firmbee.com via Unsplash))

Since checking ratings and reviews on the Chrome Web Store doesn’t seem to work in this case, you’re going to have to look for external reviews to help judge whether or not a browser extension is safe to install. However, as browser extensions rarely get full reviews, there are some other things to keep in mind to stay safe.

Just like with bad apps, the researchers found that malicious extensions often ask for more permissions than they should. If you go to install a new extension and it’s asking for quite a lot of permissions, this can be a major red flag and could be a good indication that it might be malicious.

Since many malicious extensions contain malware, you’re going to want to use the best antivirus software on your PC and one of the best Mac antivirus software solutions on your Apple computer. This way, if an extension does contain malware, your antivirus software will be able to catch it before any damage can be done.

Likewise, before you install any new software or browser extensions, you first need to ask yourself if you really need to. A lot of times, you’ll be able to accomplish the same thing using built-in software or your browser’s own capabilities. If you do need to install an extension for your browser, make sure that it’s from a trusted source or a well-known software provider.

Since Chrome is the biggest browser after all, hackers will likely keep trying to have their malicious extensions slip past Google’s defenses. The search giant does have a dedicated security team that reviews every Chrome extension to make sure it isn’t malicious though. However, if you want to be extra careful, the fewer browser extensions you have installed the better.

More from Tom's Guide

    OTHER NEWS

    24 minutes ago

    How M&S has finally fixed its fashion - for every age group: RUTH SUNDERLAND visits HQ to find out what's changed behind the scenes and what it means for investors

    27 minutes ago

    Girls join the St Paul’s Cathedral Choir for the first time

    27 minutes ago

    Mzansi reacts: Five men caught poaching R2.7 million endangered plant

    27 minutes ago

    ‘Frightening and frustrating’ move to eVisas risks repeat of Windrush scandal, experts warn

    27 minutes ago

    The Best NBA Shooting Guards In 2023-24 By Tiers

    27 minutes ago

    Gordon, Chisholm lead Marlins past Phillies

    27 minutes ago

    2 Steelers defenders named to All-Breakout team

    27 minutes ago

    As Sukhbir Badal-led Akali faction faces heat, eyes on editor of an influential Punjabi daily

    27 minutes ago

    What's Next for Mavs Following Dejounte Murray Trade?

    27 minutes ago

    Toronto area to see cooler temperatures before heat returns

    27 minutes ago

    Three Landing Spots Emerge for Klay Thompson After NBA Free Agency Decision

    27 minutes ago

    Broadcaster Derryn Hinch has revealed a new health battle

    29 minutes ago

    County Councils spend €390,000 on foreign trips for St Patrick’s Day

    29 minutes ago

    Keir Starmer mentions again how his dad 'was a toolmaker'

    29 minutes ago

    Matty Cash embraces fans after Euro 2024 snub and holiday sessions

    29 minutes ago

    Three observations from Germany’s exhausting 2-0 win against Denmark at EURO 2024

    35 minutes ago

    Celtics decline team option on NBA champ Neemias Queta

    35 minutes ago

    Stanley Cup Champion looking forward to playing with Rangers center

    35 minutes ago

    The 14th Amendment has been used to dismantle race-based programs. Historians say there are clashing interpretations

    35 minutes ago

    A Water Bottle Almost Cost John Hunter Nemechek a Win in Scorching Nashville Race

    35 minutes ago

    0630 Today in History

    35 minutes ago

    Sha'Carri Richardson finishes 4th, won't have spot in 200 meters at Olympics

    35 minutes ago

    Spurs Could Benefit From Signing Sharpshooting Free Agent

    35 minutes ago

    Michigan Bound Offensive Lineman Wins MVP Honors At Prestigious Five-Star Camp

    35 minutes ago

    Julian Nagelsmann defends Kai Havertz amid calls for Arsenal star to be benched at Euro 2024

    35 minutes ago

    UFC 303 Results: Pereira vs. Prochazka 2

    35 minutes ago

    Arne Slot's first big Liverpool transfer decision shows direction he's taking the club

    35 minutes ago

    Denmark’s Hjulmand attacks ‘ridiculous handball rules’ after defeat by Germany

    38 minutes ago

    Members of the public will not be allowed to take their phones inside Balmoral as 'bespoke' public tours of the Scottish castle get underway tomorrow

    38 minutes ago

    More than half of the population are unable to pass the UK citizenship test - but how well would YOU do?

    39 minutes ago

    Labor rebel Fatima Payman's warning to Anthony Albanese after she was suspended over rogue act

    39 minutes ago

    SARAH VINE: Whether in the name of war or the name of woke, it's always women who get it in the neck

    39 minutes ago

    Cynthia Nixon spotted filming scene for And Just Like That with new castmate Dolly Wells for the first time in NYC

    40 minutes ago

    Roseanne and Arrested Development actor dies

    40 minutes ago

    Gretchen Whitmer thinks she could beat Donald Trump, says former adviser

    40 minutes ago

    Obituary: Tommie Gorman, former RTÉ Northern editor who became a trusted figure in Irish life

    40 minutes ago

    Notions & Necessities: From foraging and foundation to GAA legends and interactive exhibitions, it’s all here

    40 minutes ago

    ‘Leather is so durable, it will be around long after us’ – fashion designer Siobhán Curtis on sustainability and strength

    40 minutes ago

    Obituary: Katie Quinn, rally driving champion who was an inspiration for her fellow female drivers

    40 minutes ago

    Airbus faces supply chain struggles, revises delivery forecasts