Removed & Compromised Extensions

A trusted browser extension can turn against you overnight — usually after it is quietly sold and the new owner pushes an update that adds tracking or outright malware. This tracker focuses on what matters if you're affected: what the extension started doing, and what to do next. Every entry is verified against the linked source before publishing.

⚠️ Active warnings

Cyberhaven (phishing-compromised build) action: Update past v24.10.4 immediately

On December 24, 2024 an attacker phished a Cyberhaven employee and published a malicious version (24.10.4) of the company's own Chrome extension, which exfiltrated cookies and authenticated sessions before Google pulled it. Researchers tied it to a wider campaign that hit dozens of other extensions.

What to do: Anyone who ran the bad build should update to a clean version, then rotate passwords and revoke active sessions for any site they used while it was installed — the extension could read authenticated cookies.

Source: Cyberhaven incident report ↗

Cyberhaven (phishing-compromised build) — full details & what to do →

Removed & compromised extensions

The Great Suspender February 4, 2021

The popular tab-suspending extension (over 2 million users) was sold to an unknown party in mid-2020. The new owner pushed an update that added tracking and remote-executed code with no source on GitHub. Google removed it from the Chrome Web Store and force-disabled it for installed users on February 4, 2021, flagging it as malware.

What affected users could do: Users had to uninstall it and switch to the community-maintained open-source fork ("The Marvellous Suspender") or a different tab manager. Any tabs held only in the extension's suspended state risked being lost when Chrome disabled it.

Source: The Register ↗

The Great Suspender — full details & what to do →

Nano Adblocker & Nano Defender October 2020

These two well-known ad-blocking extensions were sold to a new developer in October 2020. The new owner shipped an update that added malicious code which read users' session data and sent requests to a remote server — effectively turning the ad blockers against their users. They were pulled from the Chrome Web Store after the abuse was disclosed.

What affected users could do: Affected users had to remove the Chrome versions immediately and move to the original, still-trustworthy Firefox builds or a vetted alternative such as uBlock Origin. Reviewing an extension's ownership history is the lesson here.

Source: BleepingComputer ↗

Nano Adblocker & Nano Defender — full details & what to do →

Hover Zoom January 2014

Hover Zoom, an image-magnifying extension with millions of users, was caught quietly bundling code that tracked users' browsing and inserted affiliate links into the pages they visited — monetizing user activity without clear consent. The behavior was added through updates after the extension had already built a large audience.

What affected users could do: Users who relied on it had to uninstall and pick a magnifier without bundled tracking. It is a textbook example of why a once-clean extension can change after an update or a change of hands.

Source: How-To Geek ↗

Hover Zoom — full details & what to do →

If an extension you use is removed or hijacked: 4 steps, in order

  1. Remove it now — uninstall from your browser's extensions page; a compromised extension can keep reading pages and cookies until it's gone.
  2. Rotate credentials — if it had broad access, change passwords and sign out of active sessions for sites you used while it was installed (see our safety guides).
  3. Switch to a vetted replacement — prefer an open-source or long-trusted alternative; avoid extensions that recently changed hands.
  4. Check it firstrun any extension through our safety check before you reinstall.

Policy and permission changes (short of removal) are tracked separately on our policy-change alerts.