• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - A Chrome extension with millions of users has been flagged as malware and has been removed from the market

A Chrome extension with millions of users has been flagged as malware and has been removed from the market

Rocky by Rocky
March 17, 2026 - Updated on August 5, 2026
in Anti-Virus Software and Internet Security

In order to improve the speed of web pages, many web page images now use the WebP format. There is no way to save them directly as JPG or PNG. This may be very troublesome for some people. In this case, they may install the well-known “Save Image as Type” Chrome We have also introduced extended functions before (I was also a user in the past). But just recently,Google Suddenly thisExtended functionsIssue a malware warning and force deactivation. If you have installed it but it has not been deactivated, you must pay attention and remove it manually as soon as possible.


Image source: XDA Developers

The Chrome extension “Save Image as Type” installed by more than one million people was forcibly disabled by Google because it contained malicious code that stole affiliate marketing profits.

“Save Image as Type” is a free Chrome browser extension. The function is very simple. When you right-click on any image on the web page, you can directly choose to save it in PNG, JPG or WebP format, without having to rely on conversion software. This is very convenient for designers and editors who often need to download pictures, or for general users who simply want to save their favorite pictures into common formats.

Before being removed from the shelves, according to archive.today’s snapshot data at the beginning of the year, this extension already had more than 1 million users, more than 1,700 reviews, and an average rating of 4.2 stars (out of 5 stars). It was even labeled “Featured” by Google. It can be said to be one of the most popular choices among similar tools:

According to foreign media XDA Developers According to reports, Chrome recently marked this extension as malicious and forcibly disabled the version for all users. Out of curiosity, they disassembled and analyzed all versions, and even directly checked Chrome’s local storage data. They found that the problem lies in a file called “inject.js” in the extension, which is about 1.09MB in size. This malicious code will perform “Cookie Stuffing”, which is a fraudulent method of affiliate marketing:

Image source: XDA Developers

Affiliate marketing means that when you click on a recommended link from a blogger or media to buy something, the other person will receive a profit-sharing commission. This extension function secretly loads the affiliate marketing tracking link in the background through a hidden iframe, replacing the tracking cookie in your browser with its own. That way, when you later complete a purchase on those sites, the commission goes to the person behind the extension, rather than to the person who actually recommended you buy it.

Not only that, but I don’t know if it is to avoid being easily discovered. This code is also designed with multiple trigger conditions. The user must save at least 10 pictures before it can be activated, and it will only work on pages containing more than 25 pictures. According to XDA’s analysis, there are more than 578 affected websites, including Amazon, Reddit, GitHub, YouTube, BBC, Forbes and other well-known websites.

As early as two weeks ago, some netizens on Reddit reported that after installing this extension, abnormal redirection behavior would occur when browsing shopping websites such as Amazon and Best Buy:

我原本以為是 Best Buy 網站的問題。任何不是主站 .com 的連結,包括從首頁點進去的連結,都會被重新導向回首頁。後來我受不了,因為在無痕模式下完全不會發生。

Potential malicious extension. Unsure how to verify and report.
byu/UtahJarhead inchrome

If you have installed “Save Image as Type”, normally Google should have automatically disabled this extension, and a warning message will pop up in the browser. Those who are unsure can check it. Although it has been deactivated, we still recommend manually removing it from the browser to be safer.

In addition, this extension is mainly used for affiliate marketing fraud, so it will not steal account passwords or credit card information, so don’t worry about that.

Source: KOCPC Chinese

Tags: ChromeExtended functions

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology