Google pulls five Chrome Web Store extensions posing as ad blockers that had scripts enabling them to hijack browsers; extensions had 20M+ users combined
Context & Ripple Effects
This is not an isolated incident but a recurrence: back in 2015 Google disabled 192 deceptive extensions after finding 5% of its visitors had ad injectors installed, and the same cat-and-mouse has continued since. The five fake ad blockers pulled here add a sharper twist — beyond injecting ads, they carried scripts capable of hijacking browsers outright, while masquerading as tools users install precisely to block ads.
First-order effects
- More than 20 million users who installed these extensions believing they were blocking ads were instead exposed to browser hijacking scripts until Google's removal.
Second-order effects
- Advertisers and search engines bear the downstream cost when hijacked browsers distort traffic and ad delivery, echoing the injected-ads problem seen in later extension clusters.
Third-order effects
- The pattern held long after this takedown: Google went on to remove 500+ malicious extensions tied to an ad fraud network, 106 history- and credential-stealing extensions with 32M downloads, and a 295-extension cluster with 80M users inserting ads into Google and Bing results — suggesting reactive takedowns driven by researcher discoveries, not preventive vetting, remained the store's operating model.
The trend: Chrome Web Store security is settling into a cycle where researcher discoveries trigger mass takedowns of malicious extensions years apart, leaving millions of users exposed between purges.