Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The “16 extensions, over 600,000 users” figure described potential exposure in an advisory dated December 30, 2024—not 600,000 confirmed victims. On January 2, 2025, the UAE Cyber Security Council reported finding the same code in at least 35 additional extensions and estimated approximately 2.6 million users were affected overall. If you used an extension on the historical list during the campaign, uninstall it, secure accounts that were signed in through Chrome, and review them for unfamiliar activity. The figures and extension lists below are historical; they do not establish the current safety of any listing.

What happened—and how the reported numbers changed

Attackers used a phishing campaign to trick Chrome extension developers into granting access to malicious Google OAuth applications. With developer account access, they could publish malicious updates to extensions that had previously been legitimate. The UAE Cyber Security Council’s December 30, 2024 advisory said at least 16 extensions were compromised and over 600,000 users were potentially exposed to data theft and credential harvesting. It described malicious code communicating with command-and-control servers and exfiltrating cookies, access tokens, and identity information. UAE Cyber Security Council advisory, December 30, 2024.

That initial estimate was quickly superseded. In an update dated January 2, 2025, the Council reported finding the same code in at least 35 additional extensions and put the total at approximately 2.6 million users. That is an estimate of affected or potentially exposed users at the time of reporting, not a verified count of people whose data was stolen or accounts misused. UAE Cyber Security Council update, January 2, 2025.

These figures describe different snapshots of the campaign, not competing final victim counts:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Norton 360 Deluxe 2027 Antivirus, 3 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
Report Extensions reported User figure and meaning
UAE Cyber Security Council, December 30, 2024 At least 16 compromised Over 600,000 potentially exposed
UAE Cyber Security Council, January 2, 2025 At least 35 additional extensions found with the same code Approximately 2.6 million affected users overall; an estimate, not confirmed stolen accounts

Which Chrome extensions were named?

The Cyber Security Agency of Singapore published the following extensions as confirmed to carry malicious code as of December 30, 2024. This is a dated list, not a definitive list of every extension later found in the campaign: the UAE Council’s January 2 update reported at least 35 additional extensions. Cyber Security Agency of Singapore advisory.

  • AI Assistant – ChatGPT and Gemini for Chrome
  • AI Shop Buddy
  • Bard AI chat
  • Bookmark Favicon Changer
  • Castorus
  • ChatGPT Assistant – Smart Search
  • Cyberhaven security extension V3
  • Earny – Up to 20% Cash Back
  • Email Hunter
  • Internxt VPN
  • Parrot Talks
  • Primus
  • Reader Mode
  • Search Copilot AI Assistant for Chrome
  • Sort by Oldest
  • Tackker – online keylogger tool
  • TinaMind – The GPT-4o-powered AI Assistant!
  • Uvoice
  • VidHelper – Video Downloader
  • Vidnoz Flex – Video recorder & Video share
  • Visual Effects for Google Meet
  • VPNCity
  • Wayin AI

Extension names alone may not identify the exact software you had installed: similar or duplicate names can refer to different extension IDs. A historical match is a reason to take precautions, but the list does not show whether a particular current listing or build is safe. The advisories do not establish a final count of people whose data was actually stolen.

Rank #2
Sale
McAfee Total Protection 2027 Antivirus Software for 3 Devices | Auto-Renews
  • THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
  • PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
  • SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
  • GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
  • MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.

How to check whether you may have been affected

  1. Open Chrome and enter chrome://extensions in the address bar. Review installed extensions and compare their names with the historical list above.
  2. If you can, check the extension ID and version as well as its name. A name match by itself cannot confirm that two listings are the same extension.
  3. Consider when you had the extension installed and whether you used Chrome to access important accounts during that period. The campaign reports establish potential access to browser data; they do not determine whether a particular person’s information was taken.
  4. If this is a work-managed browser or account, contact your organization’s IT or security team before making changes that could affect company access or evidence.

What to do if you used a named extension

The Singapore Cyber Security Agency advised users to uninstall affected extensions, reset account passwords, clear browser data, reset browser settings to their defaults, and reinstall only if a safe version is available. eSentire also recommended rotating potentially exposed credentials and reviewing logs. The sequence below applies those recommendations while prioritizing account access.

  1. Remove the extension. In Chrome, open chrome://extensions, find the extension, and select Remove. If it is managed by your workplace, ask IT to handle it.
  2. Change passwords for important accounts you used in Chrome. Start with email, financial accounts, work accounts, and accounts that can reset other passwords. Use each service’s official site or app, not a link in an unexpected message.
  3. Revoke active sessions and tokens where the service allows it. Cookies and access tokens can act like credentials. A password change alone may not terminate every existing session, so use account security settings to sign out other sessions or revoke tokens, then sign in again.
  4. Review account activity and sign-in sessions. Look for unfamiliar devices, locations, app connections, password-reset notices, or actions you did not take. Revoke unknown sessions and report suspicious activity through the service’s official recovery process.
  5. Clear Chrome browsing data and reset browser settings. In Chrome, open More (the three-dot menu) > Settings > Privacy and security > Clear browsing data. Then open Settings > Reset settings > Restore settings to their original defaults and confirm. Chrome labels may vary by version or platform. A settings reset is not a substitute for securing accounts.
  6. Reinstall only if you can verify a safe build. Do not assume that a listing is safe just because it is currently in the Chrome Web Store. If you cannot establish that the version is safe, leave it uninstalled.

Cyberhaven: the campaign version and a separate vulnerability

Cyberhaven was an early prominent case. In an update dated January 8, 2025, eSentire said Cyberhaven confirmed that malicious version 24.10.4 had briefly been available in the Chrome Web Store. eSentire described a developer being tricked into authorizing a malicious Google OAuth application, followed by attackers using developer account access to push a trojanized extension. Its account of Cyberhaven’s investigation described theft of browser data, including authenticated sessions and cookies, with a focus on Facebook Ads-related information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Norton 360 Deluxe 2027 Antivirus, 5 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.

eSentire’s response guidance at the time was to verify Cyberhaven version 24.10.5 or newer, remove affected extensions where no secure version was available, rotate potentially exposed credentials, and review logs. This was January 2025 guidance, not a guarantee about the appropriate version or safety status today. eSentire, January 8, 2025.

A separate issue should not be confused with the campaign. In February 2025, Sonar researcher Paul Gerste reported that Cyberhaven version 24.8.2 had a vulnerability that could permit arbitrary cookie theft when a victim visited an attacker-controlled site. Sonar said Cyberhaven told the researcher it fixed that vulnerability in version 24.9.3. This predates the malicious 24.10.4 campaign version and does not establish that the vulnerability was used in the supply-chain attack. Sonar, February 26, 2025.

Rank #4
Bitdefender Total Security 2026 – Complete Antivirus and Internet Security Suite – 5 Devices | 1 Year Subscription | PC/Mac | Activation Code by Mail
  • SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows (Windows 7 with Service Pack 1, Windows 8, Windows 8.1, Windows 10, and Windows 11), Mac OS (Yosemite 10.10 or later), iOS (11.2 or later), and Android (5.0 or later). Organize and keep your digital life safe from hackers
  • SAFE ONLINE BANKING: A unique, dedicated browser secures your online transactions; Our Total Security product also includes 200MB per day of our new and improved Bitdefender VPN
  • ADVANCED THREAT DEFENSE: Real-Time Data Protection, Multi-Layer Malware and Ransomware Protection, Social Network Protection, Game/Movie/Work Modes, Microphone Monitor, Webcam Protection, Anti-Tracker, Phishing, Fraud, and Spam Protection, File Shredder, Parental Controls, and more
  • ECO-FRIENDLY PACKAGING: Your product-specific code is printed on a card and shipped inside a protective cardboard sleeve. Simply open packaging and scratch off security ink on the card to reveal your activation code. No more bulky box or hard-to-recycle discs. PLEASE NOTE: Product packaging may vary from the images shown, however the product is the same.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are the extensions safe now?

The historical advisories do not establish the current safety of every extension or version named. Listings can change, and an extension name may not identify a unique item. Check the extension ID and version against current information from the developer or your organization’s security team; if you cannot verify a safe build, do not reinstall it.

Chrome Web Store review is a safeguard, not a permanent guarantee. Google says submissions undergo a mix of manual and automated review and that published items may be reviewed periodically. Its documentation also warns that extensions with broad host permissions can access extensive web activity, creating opportunities to harvest credentials. Google describes the process as helping protect users from scams, data harvesting, malware, and malicious actors—not as eliminating the risk of a compromised developer account or a harmful future update. Google Chrome Web Store review process.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
McAfee Total Protection 2027 Antivirus Software for 5 Devices | Auto-Renews
  • THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
  • PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
  • SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
  • GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
  • MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.