Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In June 2023, security researcher Wladimir Palant reported 34 Chrome Web Store extensions containing related obfuscated code, with a combined user count of roughly 87 million in the figures available at the time. The code appeared capable of injecting JavaScript into websites, but Palant could not observe it operating or establish what it did. This is a historical security report—not evidence that every listed extension is currently available or that all users were harmed.

What happened in the June 2023 Chrome extension report?

SecurityWeek reported the story on June 5, 2023, drawing on researchers’ findings. Palant’s June 1 update listed 34 extensions and reported a combined count of 87 million, using user-count data reflecting May 30, 2023. He cautioned that his list came from a local sample and might be incomplete. Palant’s post and list provide the dated details.

Avast separately reported identifying 32 extensions with 75 million combined installs, as covered by SecurityWeek. Those are different research counts and snapshots, not figures to add together. Neither count establishes how many people installed an extension, encountered a payload, or suffered harm.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did the reported malicious code appear capable of doing?

Palant described obfuscated code that appeared designed to inject arbitrary JavaScript into websites a user visited. In his analysis, variants added code using browser tab-update and script-injection APIs. If active, that capability could enable unwanted page changes or redirects; capability alone does not establish that any particular action occurred.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

He said the configuration data returned to him was empty, so he could not observe the code operating or determine why it was inactive in his analysis. He could not tell whether it was delayed, inactive, or limited to particular regions. Palant also relayed older user reviews mentioning search redirects, but those were user reports—not direct confirmation of this campaign’s live behavior. The available account does not establish password theft, account access, or another specific impact.

Palant traced two additional variants after a reader noted that Zoom Plus contacted the same domain, serasearchtop[.]com. He described one variant as masquerading as Mozilla’s WebExtension browser API polyfill and another as masquerading as Day.js. The apparent injection capability was the concern; the actual operation remained unobserved.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Which extensions were named, and were they removed?

The reported list covered several types of browser add-ons, including ad blockers, video utilities, VPNs, downloaders, reader modes, themes, cursor customizers, tab tools, and audio controls. Examples included PDF Toolbox, Autoskip for Youtube, Crystal Ad block, Brisk VPN, Soundboost, Zoom Plus, Clipboard Helper, and OneCleaner. Names alone are not a reliable way to identify a current extension: similarly named items elsewhere may be unrelated.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Palant reported that most entries displayed Chrome’s “Featured” label at the time, an observation that illustrates why a store label should not be treated as proof of safety. His historical weekly-active-user figures for some entries were:

Rank #3
GoTrust Idem Key C USB Security Key NFC FIDO2 L2 Certified
  • Protect accounts with USB-C & NFC 2FA security key. Hardware-based authentication blocks phishing, credential theft & unauthorized access across cloud, enterprise & personal platforms.
  • FIDO2 Level 2 certified Security Key. Works with Apple ID, Microsoft Azure/Entra ID, AWS, Google, Facebook, Salesforce, DUO & more. Compatible with Chrome, Safari & Edge on all major OS.
  • Plug & play USB-C Security Key with NFC tap login. No software, drivers or batteries required. Works with Windows PC, MacBook, iPhone, Android & Chromebook for fast, secure authentication.
  • Built with FIPS 140-2 Level 3 secure element for advanced encryption. Trusted by IT teams, healthcare, education & government for secure authentication & identity protection.
  • IP68 waterproof, dustproof & crush-resistant design. Supports FIDO2, U2F, OTP, PIV, Mini Driver & smart card login. Durable USB security key for long-term enterprise & daily use.
Extension Weekly active users reported by Palant Snapshot
Autoskip for Youtube 9,008,298 May 30, 2023
Soundboost 6,925,522 May 30, 2023
Crystal Ad block 6,869,278 May 30, 2023
Brisk VPN 5,595,420 May 30, 2023

These are dated weekly-active-user counts, not current install totals. Palant’s June 2 update said all but eight had been removed from the Chrome Web Store; SecurityWeek later reported Google’s removal of the identified malicious extensions. These are 2023 store-status reports, not a current audit of every browser or store. Google also said in its Q2 2023 Chrome Security update that it had landed protections to disable installations of extensions already found to violate store policies but still enabled on users’ machines. That does not establish what happened to every user associated with this campaign.

How to check, limit, or remove Chrome extensions

Google’s current extension guidance explains how to inspect installed add-ons, change site access, and remove an extension. In Chrome:

Rank #4
FIDO2 Security Key [Folding Design] Thetis Universal Two Factor Authentication USB (Type A) for Multi-Layered Protection (HOTP) in Windows/Linux/Mac OS,Gmail,Facebook,Dropbox,SalesForce,GitHub
  • Passwordless World - A revolutionary new way to protect your account info. By being FIDO2 certified by the world’s largest ecosystem for standard-based, interoperable authentication, FIDO2 makes everyday log-in experience effortless and passwordless yet more secure than generic password style security. **Note: FIDO2 does NOT support Mac log-in.
  • Online Account Protection - FIDO2 key is backward compatible with U2F protocol and works with the newest Chrome browser with operating systems such as: Windows, macOS, or Linux. U2F can be supported and protected on all websites that follow U2F protocols.
  • Multi-factored Authentication - Built-in, advanced HOTP (One Time Password) technology that completes the unique multi-factored authentication process. Eliminate worry and help prevent losing your account info to theft, phishing, hacking, or other online scams. Note: Only Enterprise Users using Azure Active Directory can access Windows Hello log-in via Thetis FIDO2 Security Key.
  • Compact And Durable - 360° design with rotating aluminum alloy cover that shields the USB connector when not in use. Tough and durable alloy protects FIDO2 key from daily wear-and-tear, accidental drops, and scratches.
  • Portable Design - ultra-portable design allows you to take your FIDO key anywhere you need it.
  1. Open More → Extensions → Manage extensions to review the installed extensions and their details.
  2. For an extension you do not recognize or no longer need, select Remove on its card. Google also documents removal through the extension’s toolbar menu.
  3. If you still need an extension, open Details and review its permissions. Where available, limit site access to selected sites or the current site rather than allowing access everywhere.
  4. If Chrome remains affected after you repair or remove an extension, follow Google’s guidance to run antivirus or anti-malware software and remove programs that may be affecting Chrome.

Limiting host permissions is useful for controlling which sites an extension can read or change, but Google notes it does not affect extensions that alter lower-level network access through VPN or proxy settings. These steps help manage current extensions; they do not prove whether a particular extension was involved in the 2023 report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Safe Browsing can—and cannot—tell you

Google Chrome Help says: “When you use Google Safe Browsing in Chrome, you receive warnings that help protect you against malware, abusive sites and extensions, phishing, malicious and intrusive ads, and social engineering attacks.” Google’s Safe Browsing protection-level guidance distinguishes Standard protection, on by default, from Enhanced protection. Standard protection covers threats Google has already identified as dangerous. Enhanced protection can warn about potentially dangerous extensions and other items that Google may not previously know about.

That additional coverage comes with a privacy trade-off: Google says Enhanced protection sends certain URL, page-content, extension-activity, and system information to Google for security checks. Choose the level with that data sharing in mind. Safe Browsing is a protective measure, not proof that an extension is harmless or that a historical incident was remediated for every user.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.