/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google removes 106 malicious Chrome extensions with 32M downloads that collect browsing history and sensitive credentials following researcher discovery

SAN FRANCISCO (Reuters) - A newly discovered spyware effort attacked users through 32 million downloads of extensions …

Reuters Joseph Menn

Context & Ripple Effects

This is the third researcher-driven purge in four months. In February Google removed a 500-extension ad fraud network from the Web Store, in April it pulled 49 fake crypto wallet extensions that stole private keys, and the June spyware campaign follows the same script: benign-looking utilities that turn into credential harvesters at scale. The 2018 takedown of five fake ad blockers hijacking browsers shows the pattern predates this cycle.

First-order effects

  • Users across the 32M downloads had browsing history and sensitive credentials exfiltrated; removing the extensions stops collection but leaves affected users needing to rotate passwords and audit accounts on their own.

Second-order effects

  • External researchers are functioning as the Web Store's de facto review layer, which pushes Google to lean harder on post-publication takedowns rather than pre-publication vetting, and gives enterprises a reason to lock down employee extension installs.

Third-order effects

  • If each campaign keeps surfacing through researchers instead of Google's own screening, expect structural changes to how extensions are distributed — tighter permission gating or curated allowlists — as the cost of open distribution outweighs its reach benefits.

The trend: Chrome Web Store security is settling into an externally audited model where independent researchers, not platform review, are the primary line of defense against malicious extensions.

Discussion

  • @mazenmahdi Mazen Mahdi on x
    Always look for Israel “All of the domains in question, more than 15,000 linked to each other in total, were purchased from a small registrar in Israel, Galcomm, known formally as CommuniGal Communication Ltd.” https://twitter.com/...
  • @reuters @reuters on x
    Exclusive: A newly discovered spyware effort attacked users through 32 million downloads of extensions to Google's market-leading Chrome web browser, researchers at Awake Security told @Reuters https://www.reuters.com/...
  • @kaynemcgladrey Kayne McGladrey on x
    “deceptive extensions have been a problem for years, they are getting worse. They initially spewed unwanted advertisements, and now are more likely to install additional malicious programs or track where users are and what they are doing” #cybersecurity https://www.reuters.com/..…