Malware found on popular Facebook, Instagram and Vimeo browser extensions
Chrome and Edge extensions laced with malware have already been installed three million times


Malware hidden in at least 28 third-party Google Chrome and Microsoft Edge extensions has been discovered by security researchers.
The malware has the functionality to redirect user’s traffic to ads or phishing sites and to steal people’s personal data, such as birth dates, email addresses, and active devices, according to a report released by cybersecurity firm Avast.
Researchers have said that up to three million users could be affected by the malware.
The malware in question masquerades as legitimate extensions that help download videos from Instagram, Facebook, Vimeo, and other social platforms. The researchers have identified malicious code in the JavaScript-based extensions that allow the plugins to download further malware onto a user’s PC.
The threat was first spotted last month, but researchers believe the extensions could have been active for years without anyone noticing.
Users have also reported that these extensions are manipulating their internet experience and redirecting them to other websites. Anytime a user clicks on a link, the extensions send information about the click to the attacker’s control server, which can optionally send a command to redirect the victim from the real link target to a new hijacked URL before later redirecting them to the actual website they wanted to visit.
“The actors also exfiltrate and collect the user’s birth dates, email addresses, and device information, including first sign-in time, last login time, name of the device, operating system, used browser and its version, even IP addresses (which could be used to find the approximate geographical location history of the user),” the report said.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Researchers added that the objective behind this is to monetize the traffic itself. For every redirection to a third-party domain, the cyber criminals would receive a payment. Nonetheless, the extension also has the capability to redirect users to ads or phishing sites.
“Our hypothesis is that either the extensions were deliberately created with the malware built-in, or the author waited for the extensions to become popular, and then pushed an update containing the malware. It could also be that the author sold the original extensions to someone else after creating them, and then the buyer introduced the malware afterwards,” said Jan Rubín, malware researcher at Avast.
At this moment, the infected extensions are still available for download. Avast has contacted the Microsoft and Google Chrome teams to report them. Both Microsoft and Google confirmed they are currently looking into the issue. Users are recommended to disable or uninstall the extensions for now until the problem is resolved.
Extensions mentioned in the report, many of which are still available to download, include: Direct Message for Instagram, DM for Instagram, Downloader for Instagram, App Phone for Instagram, Universal Video Downloader, Vimeo Video Downloader, Volume Controller, Spotify Music Downloader, and Video Downloader for YouTube.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Google rolls out patch for high-severity Chrome browser zero day
News It's the eighth time this year Google has been forced to address a zero-day vulnerability in its world-leading browser
By Connor Jones
-
Google Chrome branded the least effective browser for stopping phishing attacks
News The world's most popular browser came dead last when compared against competitors
By Connor Jones
-
Windows devices targeted by PuzzleMaker malware exploiting Chrome zero-day flaw
News Chain of vulnerabilities used to attack multiple companies worldwide
By Rene Millman
-
Google sets a date for Chrome extension privacy revamp
News From January 18th, developers must be clear about how they're handling user data
By Danny Bradbury
-
Google looks to replace third-party cookies in two years
News The online advertising market needs to shift to tracking methods that offer some user privacy, admits Google
By Nicole Kobie
-
Chrome continues HTTP phase-out by removing 'secure' icon from HTTPS sites
News Changes in 'secure' and 'non secure' icons comprise final steps in plan to make web secure-by-default
By Keumars Afifi-Sabet
-
Hack on popular Chrome plugin spams ads to one million users
News The author says a phishing scam led to the theft of admin credentials
By Dale Walker
-
Chrome malware masquerades as 'missing font' files
News New hack tricks users into downloading missing fonts loaded with malicious files
By Dale Walker