Skip to main content

Are you using any of these browser extensions? Uninstall them now

Extensions and add-ons are a great way to get more out of your browser, but they also offer a convenient route for cybercriminals to perform a variety of nefarious acts that could threaten the security of your PC and online activities.

Security firm Avast said this week that it has identified malicious software hidden in at least 28 third-party Google Chrome and Microsoft Edge extensions. Stats from the web stores suggest the extensions have received 3 million downloads globally.

The company said the malware could potentially redirect users to phishing sites, which could lead to an attempt to steal personal data.

The extensions work with popular online platforms such as Facebook, Instagram, Spotify, and Vimeo, and help users download videos and other content from the sites.

“The researchers have identified malicious code in the JavaScript-based extensions that allows the extensions to download further malware onto a user’s PC,” Avast said, adding that users have also reported that the add-ons are manipulating their online experience and redirecting them to other websites.

“The actors also exfiltrate and collect the user’s birth dates, email addresses, and device information, including first sign-in time, last login time, name of the device, operating system, used browser and its version, even IP addresses (which could be used to find the approximate geographical location history of the user),” the security firm noted.

But Avast said the main goal appears to be to monetize the traffic itself, with the perpetrators receiving a payment for every redirection to a third-party domain.

Avast malware researcher Jan Rubín said: “Our hypothesis is that either the extensions were deliberately created with the malware built-in, or the author waited for the extensions to become popular, and then pushed an update containing the malware. It could also be that the author sold the original extensions to someone else after creating them, and then the buyer introduced the malware afterwards.”

Avast’s discovery is an important reminder to always exercise caution when downloading an extension for your browser, and to make sure you have up-to-date antivirus software enabled. Now would also be a good time to review all of your browser extensions and to uninstall those that you rarely use.

Some of the infected extensions are still available for download, though Avast said it’s contacted Microsoft and Google and both companies are now investigating the issue. Browser creators are constantly on the lookout for dodgy extensions. Google, for example, eliminated 500 of them from its Chrome Web Store earlier this year.

Below are the affected extensions discovered by Avast. If you have any of these on your PC, you’re advised to uninstall them immediately and run a scan for malware.

Direct Message for Instagram
Direct Message for Instagram
DM for Instagram
Invisible mode for Instagram Direct Message
Downloader for Instagram
Instagram Download Video & Image
App Phone for Instagram
App Phone for Instagram
Stories for Instagram
Universal Video Downloader
Universal Video Downloader
Video Downloader for Facebook
Video Downloader for Facebook
Vimeo Video Downloader
Vimeo Video Downloader
Volume Controller
Zoomer for Instagram and Facebook
VK UnBlock. Works fast.
Odnoklassniki UnBlock. Works quickly.
Upload photo to Instagram
Spotify Music Downloader
Stories for Instagram
Upload photo to Instagram
Pretty Kitty, The Cat Pet
Video Downloader for YouTube
SoundCloud Music Downloader
The New York Times News
Instagram App with Direct Message DM

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
This Chrome extension lets hackers remotely seize your PC
A depiction of a hacker breaking into a system via the use of code.

Malicious extensions on Google Chrome are being used by hackers remotely in an effort to steal sensitive information.

As reported by Bleeping Computer, a new Chrome browser botnet titled 'Cloud9' is also capable of logging keystrokes, as well as distributing ads and malicious code.

Read more
Google Chrome tops this list of most vulnerable browsers
Google Chrome logo appears over photo of laptop with chart of vulnerabilities.

According to a recent report, Google Chrome is the most vulnerability-ridden browser of all the major players. Chrome also happens to be the most popular browser in the world, accounting for over 60% of usage according to most sources, which means that a larger number of people are at risk until the bugs are fixed.

Every browser suffers from these security weaknesses from time to time, including the increasingly popular Apple Safari, Microsoft Edge, and Mozilla Firefox, but Chrome has had a startlingly high number of weaknesses in 2022. The vulnerability report from Atlas VPN summarized data found in the VulDB vulnerability database. In this year alone, 303 vulnerabilities have been detected in Google Chrome. Firefox came in a distant second with 117, while 103 were found in Edge, and only 26 in Safari.

Read more
New phishing method looks just like the real thing, but it steals your passwords
A MacBook with Google Chrome loaded.

Thanks to a new phishing method, hackers could steal all sorts of personal information by simply mimicking real login forms in Application Mode. This is a feature that's available in all Chromium-based browsers, which includes Google Chrome, Microsoft Edge, and Brave.

Using Application Mode allows threat actors to spread highly believable-looking local login forms that look like desktop applications. In reality, all inputs are sent to a malicious attacker.

Read more