• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Security company reveals large-scale malicious Chrome plug-in, downloaded nearly 33 million times

Security company reveals large-scale malicious Chrome plug-in, downloaded nearly 33 million times

Claire by Claire
June 19, 2020 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security, Latest Technology News

The reason why Chrome is so easy to use is due to its extension plug-ins. However, with many people comes a dead branch, and it seems that it has become a matter of course to mix in unscrupulous people among the many plug-ins. A security report recently disclosed by the foreign company Aiquan pointed out that there are 111 malicious extension plug-ins, with a total download count of nearly 33 million times. These plug-ins can obtain many permissions for user browser usage tracking and must be guarded against.

Security company reveals large-scale malicious Chrome plug-in, downloaded more than 32 million times

Foreign security company Awake pointed out in a report that 111 malicious or fake plug-ins were found in the Chrome extension store. According to research, these plug-ins can take screenshots of the web pages you browse, read the clipboard, steal credentials, and monitor user clicks. Among them, the most downloaded plug-ins reached 10 million times, and the total number of downloads of all plug-ins reached 32,962,951 times. It can be said to be one of the largest malicious behaviors in recent times.
【To view the full report, click here】

What these malicious plug-ins have in common is that they all establish connections through Internet domain names registered by Galcomm in Israel. Researchers eventually found that more than 15,000 hosts registered with the company had malicious or suspicious behavior, and they used various evasion techniques to avoid being flagged by security protection products. After analysis, it was found that malicious activity participants had established outlets in more than 100 network domains including financial services, oil and gas, media and entertainment, healthcare and pharmaceuticals, retail, high technology, higher education, and government agencies. Many extensions are modular, meaning that after a user installs them, they are automatically updated with executable files that are in many cases specific to the operating system they are running on.
★Because the Chrome Extension Store only recognizes IDs and allows the same name, most of these problematic plugins exist under these names:
browse-safer
browsing-protector
browsing-safety-checker
bytefence-secure-browsing
convertwordtopdf
doctopdf
easyconvert
easyconvertdefault-search
gofiletopdf
mydocstopdf
pdf2doc
pdf-ninja-converter
pdf-opener
quicklogin
quickmail
search-by-convertfilenow
search-by-convertpdfpro
search-manager
secured-search-extension
secure-web-searching
securify-for-chrome
thedocpdfconverter
theeasywaypro
thesecuredweb-protected-b
ttab
viewpdf


▲The intersection of these malicious extensions

These plug-ins appear as various file readers, and they are also disguised as network security enhancement applications. However, few of these plug-ins can provide corresponding functions as described in their introduction. Awake said the nearly 33 million downloads figure is based on extensions in the Chrome Web Store in early May, so it may ignore add-ons that were available earlier but were subsequently removed; the figure also doesn’t include extensions obtained from sources outside the Chrome Web Store.

Although the nearly 33 million downloads may be exaggerated by false reports, it is undeniable that the number of infected devices is also quite staggering, and Google has urgently removed these extensions from the shelves. I would like to remind everyone that users of any browser should carefully choose extension applications to install only when the extension can provide practical uses, and mainly use extensions issued by reputable developers, or install them after referring to credible media, research websites, or community forums for reviews. Don’t lose your guard when you see a lot of downloads, and don’t forget to read the comments about the plug-in. If there are any comments about suspicious behavior, you’d better not download and use it.

◎Data source:Arstechnica、Awake

Source: KOCPC Chinese

Tags: BrowserChromeExtended applicationExtension plug-inhackerInternet securityMalicious plug-insplug-in

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology