There are so many Chrome extensions containing malicious code! Every once in a while, a new one comes, and this time even the Edge browser, which has just been switched to Chromium core, won the bid. Earlier, Avast security company announced the latest 28 malicious extensions they discovered. In addition to collecting personal information and browsing history, some even install malware on users’ computers. Currently, more than 3 million users have installed them. Come and check them out.

Expanded list of 28 Chrome and Edge plugins containing malicious code
The 28 malicious extensions and plug-ins released by Avast are as follows. Most of the Chrome versions have been deleted at present, but some of them are still on the store shelf in Edge. If you are not sure whether you have installed them, you can open the list of installed extensions and plug-ins, and then compare them by name and delete them if you are suspicious:
Chrome extension plug-in list
- Direct Message for Instagram
- DM for Instagram
- Invisible mode for Instagram Direct Message
- Downloader for Instagram
- App Phone for Instagram
- Stories for Instagram
- Video Downloader for FaceBook™
- Vimeo™ Video Downloader
- Zoomer for Instagram and FaceBook
- VK UnBlock. Works fast.
- Odnoklassniki UnBlock. Works quickly.
- Upload photo to Instagram™
- Spotify Music Downloader
- The New York Times News
Edge expanded plug-in list
- Direct Message for Instagram™
- Instagram Download Video & Image
- App Phone for Instagram
- Universal Video Downloader
- Video Downloader for FaceBook™
- Vimeo™ Video Downloader
- Volume Controller
- Stories for Instagram
- Upload photo to Instagram™
- Pretty Kitty, The Cat Pet
- Video Downloader for YouTube
- SoundCloud Music Downloader
- Instagram App with Direct Message DM
According to Avast, they discovered these expansion plug-ins last month. Some of them were launched in December 2018, which means it has been a long time. Moreover, some of the expansion plug-ins have user feedback that will automatically be directed to other websites.

The following is the malicious code found, including “directing users to ads”, “directing users to phishing websites”, “collecting user personal information such as birthday, email and enabled devices”, “collecting browsing history” and “downloading malware to the user’s device”.

It can also be clearly seen from the list that many of them are very popular extension plug-ins, such as tools that can download Instagram, Facebook, Vimeo, YouTube videos, and Spotify and SoundCloud music. This means that if you have ever searched for similar keywords, you must check it out.
Source: KOCPC Chinese