Security research attributed to Q Continuum reported 287 Chrome extensions that transmit users’ browsing history to third parties, affecting an estimated 37.4 million installations. The work used automated analysis (including containerized scanning and man-in-the-middle proxy inspection of extension traffic) to flag suspicious outbound communications consistent with URL/history leakage, and noted that some extensions use obfuscation and encryption (e.g., ROT47 and AES-256 with RSA key pairs) to conceal collection and exfiltration behavior.
The identified ecosystem includes extensions tied to data-broker/analytics activity, with reporting naming Similarweb and related entities (including “Big Star Labs”) among organizations operating extensions implicated in history collection, alongside other groups controlling additional high-install extensions. While some data sharing may be disclosed in privacy policies, the reporting emphasized that browsing history can be highly sensitive and, even when “anonymized,” can often be re-identified, creating material privacy and compliance risk for users and organizations that allow unmanaged browser extensions.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage added that some extensions used plaintext, Base64, ROT47, AES-256, and RSA-based protection to conceal exfiltrated browsing data. Reports also highlighted risks such as deanonymization, exposure of internal corporate URLs and SaaS links, and possible credential or session-related abuse if additional browser data were collected.
The researcher disclosed an automated testing pipeline using Docker, Chromium, synthetic browsing, and a man-in-the-middle proxy to detect history leakage from extensions. The analysis named recipients and collectors including Similarweb, Big Star Labs, Semrush, Alibaba Group, ByteDance, Curly Doggo, and Offidocs, while noting roughly 20 million affected installs could not be tied to a known entity.
Security researcher Q Continuum reported finding 287 Google Chrome extensions that exfiltrate users' browsing history, affecting an estimated 37.4 million installations. The research said many extensions appeared benign while requesting access to history data and sending visited-URL information to third parties.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
5 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcecsoonline.com
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.