A trusted Chrome extension, Save Image as Type, was removed after researchers found it had been hijacked and modified to perform affiliate commission fraud against more than 1 million users. The malicious code reportedly redirected shopping traffic in the background on sites including Amazon, Adidas, and Shein, while the extension continued to function normally, making the abuse difficult for users to notice. Reporting attributes the compromise to a group called Karma, which allegedly acquires established browser extensions from their original developers and then injects malicious code to monetize the existing user base.
Separate research shows how easily this model can work in practice: browser extensions can be sold to new owners, transferring not just code but also user trust and broad permissions. A proof-of-concept described by Annex Security demonstrated that an extension could be purchased cheaply and then repurposed, underscoring the supply-chain risk created when ownership changes are not visible to users. Together, the reporting and research highlight a growing threat in which legitimate extensions become malicious after sale or takeover, allowing attackers to exploit previously trusted add-ons at scale.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
Google removed the "Save Image as Type" extension in March 2026 after researchers found it had been hijacked for affiliate commission fraud. Reports said the malicious version may have been active for several weeks before the takedown, and users were advised to uninstall it.
Research by Wladimir Palant connected Karma to a wider pattern of purchasing trusted browser extensions and later inserting malicious payloads. This attribution expanded the story from a single hijacked extension to a broader campaign model.
Annex Security researcher John Tuckner published a proof of concept showing that buying a Chrome extension for about $50 allowed him to push an update to installed users that redirected them to a Rickroll. The demonstration showed how extension ownership transfers can give a new owner automatic control over users' browser behavior through normal update mechanisms.
The Chrome extension QuickLens, which reportedly had about 7,000 users and a Google featured badge, was sold to a new owner and then updated with command-and-control functionality, expanded permissions, and code that weakened browser security protections. The malicious update allegedly used an invisible 1×1 pixel injection technique and stripped protections such as Content Security Policy to enable JavaScript execution on visited pages.
After the acquisition, the extension was modified to silently redirect shopping traffic on sites including Amazon, Adidas, and Shein so the operators could collect affiliate commissions. The extension continued to function normally as an image conversion tool, helping the malicious behavior avoid detection.
The Chrome extension "Save Image as Type," which had more than 1 million users, was reportedly acquired by a group called Karma. The later abuse was tied to this ownership change, illustrating the supply-chain risk of sold browser extensions.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.