Home
 » ISP News » 
Sponsored Links

Check Now – 18 Trusted Web Browser Extensions Discovered Stealing Your Data

Thursday, Jul 10th, 2025 (8:20 am) - Score 1,920
Website browser on a computer

Researchers from Kai Security have identified eighteen extensions (add-ons) for Google’s Chrome and Microsoft’s Edge website browsers, some of which are both well rated and widely installed, that have been stealthily used to hide a Trojan infection that can hijack your browser and steal personal data. Worse is that 2.3 million users have installed one of them.

The extensions themselves are often quite clever in the sense that they actually deliver on the features they claim in public and often only add the Trojan much later (sometimes years later). As a result, many of them have been around for years, earning good reviews and a degree of trust. Not to mention that Microsoft and Google clearly have not previously discovered any problems via their limited checks and balances.

This isn’t some obvious scam extension thrown together in a weekend. This is a carefully crafted Trojan horse that delivers exactly what it promises while simultaneously hijacking your browser, tracking every website you visit, and maintaining a persistent command and control backdoor. Not only that, but it remained legitimate for years before becoming malicious through a version update,” said Idan Dardikman of Kai Security about one of the identified extensions.

Advertisement

Due to how Google and Microsoft handle browser extension updates, these malicious versions auto-installed themselves silently, often without end-users needing to click anything. “No phishing. No social engineering. Just trusted extensions with quiet version bumps that turned productivity tools into surveillance malware,” added Idan. “Every click, every website visit, every online transaction becomes a potential attack vector.

Kai Security first discovered this while investigating the ‘Color Picker, Eyedropper — Geco colorpick‘ extension, before later identifying it as being just the tip of a “sophisticated cross-platform network” of eighteen malicious extensions spanning both Chrome and Edge stores, all sharing the same hijacking functionality. The team have dubbed this as the RedDirection campaign.

The extensions span across a diverse set of categories including emoji keyboards, weather forecasters, video speed controllers, VPN proxies for Discord and TikTok, dark themes, volume boosters, and YouTube unblockers. But if you’ve read this far, then you’d probably rather we just skipped ahead to list the ones you need to check and remove.

Extension IDs

Chrome:

  • kgmeffmlnkfnjpgmdndccklfigfhajen — [Emoji keyboard online — copy&past your emoji.]
  • dpdibkjjgbaadnnjhkmmnenkmbnhpobj — [Free Weather Forecast]
  • gaiceihehajjahakcglkhmdbbdclbnlf — [Video Speed Controller — Video manager]
  • mlgbkfnjdmaoldgagamcnommbbnhfnhf — [Unlock Discord — VPN Proxy to Unblock Discord Anywhere]
  • eckokfcjbjbgjifpcbdmengnabecdakp — [Dark Theme — Dark Reader for Chrome]
  • mgbhdehiapbjamfgekfpebmhmnmcmemg — [Volume Max — Ultimate Sound Booster]
  • cbajickflblmpjodnjoldpiicfmecmif — [Unblock TikTok — Seamless Access with One-Click Proxy]
  • pdbfcnhlobhoahcamoefbfodpmklgmjm — [Unlock YouTube VPN]
  • eokjikchkppnkdipbiggnmlkahcdkikp — [Color Picker, Eyedropper — Geco colorpick]
  • ihbiedpeaicgipncdnnkikeehnjiddck — [Weather]

Edge:

  • jjdajogomggcjifnjgkpghcijgkbcjdi — [Unlock TikTok]
  • mmcnmppeeghenglmidpmjkaiamcacmgm — [Volume Booster — Increase your sound]
  • ojdkklpgpacpicaobnhankbalkkgaafp — [Web Sound Equalizer]
  • lodeighbngipjjedfelnboplhgediclp — [Header Value]
  • hkjagicdaogfgdifaklcgajmgefjllmd — [Flash Player — games emulator]
  • gflkbgebojohihfnnplhbdakoipdbpdm — [Youtube Unblocked]
  • kpilmncnoafddjpnbhepaiilgkdcieaf — [SearchGPT — ChatGPT for Search Engine]
  • caibdnkmpnjhjdfnomfhijhmebigcelo — [Unlock Discord]

Kai Security recommends that anybody who has installed one of these browser extensions should, obviously, remove them, then clear your browser data/cache, run a full system malware scan, monitor your online accounts and also conduct a review of all your other extensions.

Advertisement

The attackers didn’t just evade Google and Microsoft’s review process; they systematically exploited it at scale, turning the marketplace into a distribution platform for sophisticated surveillance malware,” concluded Idan. Clearly, Microsoft and Google need to re-think their current approach to extension security and updates, particularly as some of these add-ons are still available for download from some of the official stores (e.g. here).

Share with Twitter
Share with Linkedin
Share with Facebook
Share with Reddit
Share with Pinterest
Mark-Jackson
By Mark Jackson
Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook, BlueSky, Threads.net and .
Search ISP News
Search ISP Listings
Search ISP Reviews
Comments
9 Responses

Advertisement

  1. Avatar photo Far2329Light says:

    I never use extensions. You should always assume that downloaded software is infected or hijacked unless it comes from a verified and reliable resource.

    1. Avatar photo tonyp says:

      I thought Microsoft and Google were reliable sources that verified their extensions! I’m now wondering what might be found in Firefox – my preferred browser. I’m wondering if the afore listed extensions apply to all underlying OS’s – eg. ChromeOS, Windows, Linux? I suspect so.

  2. Avatar photo greggles says:

    Usually the strategy is to either buy a extension that had a legit dev, and then change it after ownership change, or initially have a legit extension, then after its grown in popularity to change it.
    For this reason auto upgrading extensions is bad security practice. Side loading is better as they dont auto upgrade.

    1. Avatar photo Lonpfrb says:

      Side loading means 100% own responsibility for hygiene of that software so is bad practice for the majority of users unable to do that.
      The app stores remain the best trusted source for the majority of users.
      As this article suggests they can also be improved as cyber security is an endless war of innovation.

  3. Avatar photo Winston Smith says:

    Alternatively use Firefox.

  4. Avatar photo Trump's Wig says:

    Everything is trying to steal your data, most software have now made it so you willingly hand it all over like Discord
    An application mascarading as a voice communication app but in reality it’s syphoning up every single thing happening in the PC it’s installed on
    Programmes launched, how often, what time etc etc etc
    It’s blatant malware disguised as a helpful tool people install and agree to seriously dodgy levels of data collection

    1. Avatar photo Michael Bradbrook says:

      You could say also about the browser that you use as well, especially Edge and Chrome. As you know, they take snapshots of everything that you are doing on their browser and collect the data. That’s why I try and dodge them two as much as possible. Even Firefox has come under fire for changing its stand on privacy, that is why I use a fork version of Firefox like Librewolf which is privacy driven and backed up with an ad blocker like uBlock Origin.

  5. Avatar photo NE555 says:

    Citation Needed™

Comments are closed

Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
200Mbps
Gift: None
Youfibre UK ISP Logo
Youfibre £23.99
150Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £23.99
132Mbps
Gift: None
Plusnet UK ISP Logo
Plusnet £24.99
145Mbps
Gift: £145 Reward Card
NOW UK ISP Logo
NOW £25.00
100Mbps
Gift: None
Large Availability | View All
Cheap Unlimited Mobile SIMs
iD Mobile UK ISP Logo
iD Mobile £16.00
Contract: 24 Months
Data: Unlimited
Talkmobile UK ISP Logo
Talkmobile £16.95
Contract: 1 Month
Data: Unlimited
Smarty UK ISP Logo
Smarty £17.00
Contract: 1 Month
Data: Unlimited
ASDA Mobile UK ISP Logo
ASDA Mobile £19.00
Contract: 24 Months
Data: Unlimited
Three UK ISP Logo
Three £20.00
Contract: 24 Months
Data: Unlimited
Cheapest ISPs for 100Mbps+
toob UK ISP Logo
toob £18.00
150Mbps
Gift: None
Gigaclear UK ISP Logo
Gigaclear £19.00
300Mbps
Gift: None
Community Fibre UK ISP Logo
200Mbps
Gift: None
Beebu UK ISP Logo
Beebu £23.00
100 - 160Mbps
Gift: None
Hey! Broadband UK ISP Logo
150Mbps
Gift: None
Large Availability | View All
Promotion
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms , Privacy and Cookie Policy , Links , Website Rules , Contact
Mastodon