-
4 minutes, 15 seconds
Security researchers have uncovered 17 new malicious browser extensions affecting Chrome, Firefox, and Edge, collectively downloaded over 840,000 times. These extensions secretly monitored user activity, injected tracking scripts, hijacked affiliate links, and enabled ad fraud. While all extensions have been removed from official stores, users must manually uninstall them to secure their devices.
This wave of malware is linked to Operation GhostPoster, a campaign first spotted in December 2025. GhostPoster continues to evolve, indicating that malicious actors are persistent and constantly adapting to bypass browser security measures.
The malicious extensions were designed to stay hidden while performing a variety of harmful tasks. Researchers found that they injected JavaScript code stored in PNG logos to execute payload downloads. This clever method allowed the malware to remain undetected by browser security systems while gaining persistent access to affected devices.
Most extensions first appeared in Microsoft Edge’s store before spreading to Chrome and Firefox. Some have been on official repositories since 2020, showing that users have potentially been exposed to malware for years without knowing it.
LayerX has identified the following extensions as part of the latest GhostPoster campaign:
Google Translate in Right Click
Translate Selected Text with GoogleAds Block Ultimate
Floating Player – PiP Mode
Convert Everything
YouTube Download
One Key Translate
AdBlocker
Save Image to Pinterest on Right Click
Instagram Downloader
RSS Feed
Cool Cursor
Full Page Screenshot
Amazon Price History
Color Enhancer
Translate Selected Text with Right Click
Page Screenshot Clipper
Each of these extensions performed tracking, ad injection, or data theft, often without the user’s knowledge.
Even after removal from stores, users who installed these extensions remain vulnerable until they uninstall them manually. Attackers often exploit these extensions to steal credentials, monitor browsing habits, or manipulate online ad revenue. Experts warn that browsers alone cannot protect users from malicious extensions; proactive removal and careful scrutiny of permissions are essential.
Additionally, the campaign demonstrates the growing sophistication of browser-based malware. By storing executable code in image files and using legitimate-looking names, malicious actors can bypass traditional detection methods and reach a wider audience.
Users should immediately review their installed browser extensions and remove any suspicious or unnecessary items. Checking extension permissions, reading recent reviews, and staying updated on security advisories can prevent similar threats. Experts also recommend limiting installations to trusted sources and disabling extensions that request excessive access.
Cybersecurity teams continue to track GhostPoster and similar campaigns, emphasizing that vigilance is critical. Even seemingly harmless browser tools can become powerful vectors for malware if proper safeguards are not followed.
The GhostPoster campaign highlights how malicious extensions can remain active for years and continue to impact millions of users worldwide. Security experts stress that manual audits of browser extensions, along with regular software updates, remain the most effective way to mitigate risks. Users must act fast to remove infected extensions and prevent potential data theft or ad fraud.
Comment