A trusted browser extension can turn against you overnight — usually after it is quietly sold
and the new owner pushes an update that adds tracking or outright malware. This tracker focuses
on what matters if you're affected: what the extension started doing, and what
to do next. Every entry is verified against the linked source before publishing.
⚠️ Active warnings
Cyberhaven (phishing-compromised build)action: Update past v24.10.4 immediately
On December 24, 2024 an attacker phished a Cyberhaven employee and published a malicious version (24.10.4) of the company's own Chrome extension, which exfiltrated cookies and authenticated sessions before Google pulled it. Researchers tied it to a wider campaign that hit dozens of other extensions.
What to do: Anyone who ran the bad build should update to a clean version, then rotate passwords and revoke active sessions for any site they used while it was installed — the extension could read authenticated cookies.
The popular tab-suspending extension (over 2 million users) was sold to an unknown party in mid-2020. The new owner pushed an update that added tracking and remote-executed code with no source on GitHub. Google removed it from the Chrome Web Store and force-disabled it for installed users on February 4, 2021, flagging it as malware.
What affected users could do: Users had to uninstall it and switch to the community-maintained open-source fork ("The Marvellous Suspender") or a different tab manager. Any tabs held only in the extension's suspended state risked being lost when Chrome disabled it.
These two well-known ad-blocking extensions were sold to a new developer in October 2020. The new owner shipped an update that added malicious code which read users' session data and sent requests to a remote server — effectively turning the ad blockers against their users. They were pulled from the Chrome Web Store after the abuse was disclosed.
What affected users could do: Affected users had to remove the Chrome versions immediately and move to the original, still-trustworthy Firefox builds or a vetted alternative such as uBlock Origin. Reviewing an extension's ownership history is the lesson here.
Hover Zoom, an image-magnifying extension with millions of users, was caught quietly bundling code that tracked users' browsing and inserted affiliate links into the pages they visited — monetizing user activity without clear consent. The behavior was added through updates after the extension had already built a large audience.
What affected users could do: Users who relied on it had to uninstall and pick a magnifier without bundled tracking. It is a textbook example of why a once-clean extension can change after an update or a change of hands.
If an extension you use is removed or hijacked: 4 steps, in order
Remove it now — uninstall from your browser's extensions page; a compromised extension can keep reading pages and cookies until it's gone.
Rotate credentials — if it had broad access, change passwords and sign out of active sessions for sites you used while it was installed (see our safety guides).
Switch to a vetted replacement — prefer an open-source or long-trusted alternative; avoid extensions that recently changed hands.