Could that helpful add-on be collecting your data and redirecting you without a hint?
Extensions add convenience, but a handful of malicious add-ons have been known to behave normally, then flip after an update and start siphoning URLs, sending identifying IDs to remote servers, and redirecting visits to phishing pages.
Recent research exposed a campaign of 18 harmful add-ons with millions of installs. In one real-world case, clicking a meeting link sent users to a fake update that installed further malware and put devices at risk.
This short guide shows practical steps users can run: inventory installed extensions, vet permissions, spot store-page red flags, and test what information an add-on transmits. For background reporting, see a detailed analysis at Bleeping Computer and related risks like open redirects explained at Haktechs.
Key Takeaways
- Malicious extensions can start clean, then deploy harmful updates that capture data and hijack navigation.
- Simple inventory and permission reviews reduce exposure quickly.
- Watch for invisible signs: tracking beacons or obfuscated callbacks.
- Limit site access and prune unused add-ons to lower risk.
- Test suspicious behavior before trusting an extension with sensitive accounts.
Why extensions can spy on you and how the risk has evolved
Attackers have learned to hide malicious functionality behind long periods of normal behavior. That deliberate delay lets harmful code pass store reviews, reach many users, then flip to theft or redirects.
From sleeper agents to malicious updates:
From sleeper agents to malicious updates
Researchers discovered campaigns that began with benign add-ons and later shipped updates that captured every visited URL and tagged it with a unique tracking ID. One cluster hit official stores and amassed millions of installs before activating.
“An enterprise extension used by 400,000 customers was briefly poisoned and exfiltrated cookies and session tokens for major sites.”
The dual threat: data exfiltration and browser fingerprinting
Data theft plus extension-based fingerprinting
Malicious updates can steal credentials and session tokens. At the same time, browser fingerprint techniques let websites detect installed add-ons and track users across websites even after cookies clear.

| Item | Modern extension | Legacy plugin (NPAPI) |
|---|---|---|
| Technology | HTML/CSS/JS, sandboxed | Binary native code (deprecated) |
| Risk | Data access, tracking, updates can exfiltrate info | System-level exploits, mostly phased out |
| Store presence | Hosted in web store / chrome web store | Removed from modern stores since 2015–2017 |
Practical note: attackers often use account takeovers or obfuscation and wake malicious code after delivery. Treat updates like supply-chain events and watch for sudden permission creep. For deeper incident examples, read this analysis at Malwarebytes and guidance on cleanup at Haktechs.
How to check if browser extensions are spying on you
Start with a short inventory and targeted inspections. An accurate list of your extensions makes it easier to spot permission creep and odd behavior quickly.

Where to find your extensions
Chrome: open chrome://extensions or use the puzzle-piece menu > Manage Extensions and click Details.
Edge: visit edge://extensions, then open Details; options mirror Chrome.
Firefox: open Add‑ons and Themes (about:addons) and review the add‑on page on addons.mozilla.org for full prompts.
Safari (macOS): Safari > Settings > Extensions, then use Edit Websites for per-site controls. On iPhone/iPad, use Settings > Safari > Extensions.
What to look for on the details and store page
Inspect permissions for broad items like read and change all your data on all websites, reading history, or automatic updates. Limit site access to On click or specific sites in Chromium-based settings.
“Broad site permissions are the most common root cause of silent data leaks.”
Quick action checklist
- Build a list of extensions installed and flag unknown publishers.
- Set site access to specific sites or on‑click where available.
- Review store reviews and update history; beware sudden permission jumps.
- Disable suspect items and re-enable one at a time to isolate issues.
| Step | Where | What to watch for |
|---|---|---|
| Inventory | Chrome, Edge, Firefox, Safari | Unknown names, high install counts, broken support links |
| Permissions review | Details / Add‑on page | Read/change site data, history access, auto‑updates |
| Operational test | Your regular websites | Redirects, search changes, injected ads or toolbars |
If detection feels unclear, remove the extension and search for safer alternatives. For a practical detection guide and network checks, see a concise walk‑through at plugin detection guide. For related web vulnerabilities that may interact with add‑on behavior, review this primer on cross‑site scripting risks at XSS vulnerabilities.
Go deeper: verify what data an extension sends and when
A direct inspection reveals whether a plugin collects full page URLs, cookies, or session tokens. Set up an isolated VM with Firefox and an intercepting proxy to watch requests without risking your main profile.

Start simple. Look for sudden spikes in outbound web traffic, frequent background requests when idle, or repeated sign‑in prompts that could show token harvesting. Document any odd domains and repeated endpoints you did not expect.
- Run OWASP ZAP locally, trust its certificate in Firefox, and route traffic via localhost:8080 to inspect HTTPS requests.
- Visit neutral pages and filter captures for requests that include full url fields, cookies, or session parameters.
- Decode base64 payloads; many contain host, target (full url), last (previous page), and referrer — data that may be transmitted every time you navigate.
In one real example, the Web of Trust plugin produced URL‑encoded form data that after decoding showed host, target, last, referrer, and timing metadata. Debugging the add‑on in about:debugging let the researcher set breakpoints in crypto code and inspect the request build process. By contrast, uBlock Origin sent no outbound data in that test.
“Encoded or binary blobs that decode to opaque fields likely indicate encryption or hidden data flows; treat these as a warning sign.”
When you see identifiers, tokens, or ad tech parameters leave the client, remove the plugin and record contacted domains. For context on rogue add‑on reporting, read this Chrome VPN report and review hardening tips at site security guidance.
Remove, recover, and harden your browser
Act fast to remove a suspect extension, clear site data, and restore safe defaults. These steps cut off stolen tokens, undo unwanted changes, and reduce the chance of repeat infections.
A short clean-up playbook keeps recovery focused and repeatable. Begin by uninstalling the suspect extension, then immediately clear history, cookies, cached files, and all site data to invalidate captured session tokens and tracking identifiers.

Clean-up playbook
- Remove the suspect extension and reboot the browser.
- Clear browsing data (history, cookies, cache, site data) and sign back into critical accounts.
- Reset settings to defaults if search, homepage, or toolbars changed.
- Update your browser and remaining extensions; then run a full anti‑malware scan (for example, Malwarebytes).
- Change passwords for accounts used during the exposure window and enable two‑factor authentication (2FA).
Prevention tips
Minimize installed extensions and enforce permission discipline. Keep only essential extension functionality and set site access to on‑click or to specific websites. Pin trusted versions for critical tooling where policy allows to prevent malicious auto‑updates.
Train users to spot redirects, odd popups, or new permission requests and report them quickly. For a practical removal walkthrough, see this detect and remove spyware guide, and for broader server hardening read harden your Apache server.
Known malicious extensions and indicators to check against
This list highlights concrete IDs, domain patterns, and behaviors that security-minded users and admins should watch for. Use these markers as a starting point for a focused audit of extensions installed across profiles and managed fleets.

- Chrome IDs: kgmeffmlnkfnjpgmdndccklfigfhajen (Emoji keyboard online); dpdibkjjgbaadnnjhkmmnenkmbnhpobj (Free Weather Forecast); gaiceihehajjahakcglkhmdbbdclbnlf (Free Weather Forecast); mlgbkfnjdmaoldgagamcnommbbnhfnhf (Unlock Discord); eckokfcjbjbgjifpcbdmengnabecdakp (Dark Theme); mgbhdehiapbjamfgekfpebmhmnmcmemg (Volume Max); cbajickflblmpjodnjoldpiicfmecmif (Unblock TikTok); pdbfcnhlobhoahcamoefbfodpmklgmjm (Unlock YouTube VPN); eokjikchkppnkdipbiggnmlkahcdkikp (Geco colorpick); ihbiedpeaicgipncdnnkikeehnjiddck (Weather).
- Edge IDs: jjdajogomggcjifnjgkpghcijgkbcjdi (Unlock TikTok); mmcnmppeeghenglmidpmjkaiamcacmgm (Volume Booster); ojdkklpgpacpicaobnhankbalkkgaafp (Web Sound Equalizer); lodeighbngipjjedfelnboplhgediclp (Header Value); hkjagicdaogfgdifaklcgajmgefjllmd (Flash Player); gflkbgebojohihfnnplhbdakoipdbpdm (Youtube Unblocked); kpilmncnoafddjpnbhepaiilgkdcieaf (SearchGPT); caibdnkmpnjhjdfnomfhijhmebigcelo (Unlock Discord).
Suspicious domains and lookalikes: admitab[.]com, edmitab[.]com, click.videocontrolls[.]com, c.undiscord[.]com, click.darktheme[.]net, c.jermikro[.]com, c.untwitter[.]com, c.unyoutube[.]net, admitclick[.]net, addmitad[.]com, admiitad[.]com, abmitab[.]com, admitlink[.]net.
What behavior to verify
Watch for code that captures the full page URL every time you navigate and attaches a unique identifier. That pattern often signals tracking or a command-and-control beacon.
- Unexpected redirects to installers or fake update pages (example: a bogus meeting link that leads to a malware installer).
- Background requests from an extension with full-page url fields, repeated on idle.
- Store entries with copycat names in the chrome web store or Edge web store and sudden publisher changes.
Actionable steps: search your extensions installed for any IDs above; remove matches, clear browsing data, and reset settings. Review proxy captures for calls to the listed domains and block them via DNS or firewall. Enterprise admins should compile these IDs in a blocklist and enforce policies in the chrome web store management console.
For deeper reading on malicious add‑on behavior and prevention, see this investigation into manipulative plugins at malicious extensions analysis and server-side attack prevention guidance at drive‑by download hardening.
Conclusion
Small add-ons can carry outsized risk. Treat browser extensions like full software: keep only those you need, review permissions often, and set site access to on click or specific sites. A strong, routine audit reduces exposure and narrows tracking footprints across websites.
Organizations should limit which extensions staff install, pin trusted versions, and run regular audits. For technical readers, a formal study of spying extensions is useful background: see the spying extension study.
Start with an inventory today. Prune unused items, favor reputable publishers, and isolate sensitive sessions in a clean profile. Vigilance and least‑privilege access are the best defenses for long‑term browser security.