Malicious and unwanted browser extensions continued to pose a significant threat to users, including through official browser stores and add-ons disguised as legitimate tools. Kaspersky reported that from January 2020 through June 2022, more than 6 million users were blocked from downloading malware, adware, or riskware presented as browser extensions, with adware making up most detections. The report identified several prominent families, including WebSearch, DealPly-related extensions, AddScript, and FB Stealer, each using different delivery and monetization methods.
The extensions were distributed through third-party software bundles, malicious updates, and cases where an extension changed hands or a developer account was hijacked after publication. Their activity ranged from affiliate abuse and cookie stuffing to covert script execution and credential theft, with FB Stealer highlighted as particularly dangerous because it steals Facebook session cookies and enables account hijacking. The findings underscored that browser extensions can become a persistent attack surface even when they appear benign, especially when users grant broad permissions or install unnecessary add-ons.

Trace attribution and downstream blast radius.
11 events from the most recent confirmed update back to the earliest known activity.
Imperva Research Labs uncovered an ad-injection campaign tied to the AllBlock browser extension for Chrome and Opera, which injected malicious code into tabs and hijacked clicks to affiliate URLs. Imperva also linked the infrastructure to an older PBot campaign and published related indicators of compromise.
In 2021, 1,823,263 unique users attempted to download malicious or unwanted browser extensions. The figure showed the threat remained widespread after the 2020 peak.
The number of unique users affected by malicious or unwanted browser extensions peaked in 2020 at 3,660,236, according to Kaspersky telemetry. This marked the highest annual impact level in the period discussed.
In 2020, Google removed 106 malicious browser extensions from the Chrome Web Store. Before removal, they had been downloaded 32 million times and were used to steal cookies and passwords and take screenshots across more than 100 abused networks.
The AddScript browser-extension threat family was first seen in early 2019. The report notes it was still active in 2022.
Early variants of the DealPly-related adware browser extensions appeared in late 2018. These extensions were associated with adware that modified browser settings and redirected users to affiliate sites.
From January 2020 through June 2022, Kaspersky products prevented 6,057,308 users from downloading malware, adware, and riskware disguised as browser extensions. Over the same period, adware accounted for about 70 percent of affected users, with more than 4.3 million attacked by adware and more than 2.6 million by malware.
Between January and June 2022, 97,515 unique Kaspersky users encountered DealPly-related extensions. These were typically installed by the DealPly adware executable rather than directly by users.
In the first half of 2022, 156,698 unique users encountered the AddScript browser-extension threat family. The report identifies it as an active threat family first seen in 2019.
In the first half of 2022, WebSearch was the most common browser-extension threat in Kaspersky telemetry, affecting 876,924 unique users. The adware commonly masqueraded as document-related tools and changed browser settings to collect queries and promote affiliate links.
A malicious Google Chrome extension available in the official store was found capable of recognizing and stealing payment card details entered into web forms. Google removed the extension after it had already infected more than 400 users.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.