Founder of Secure Annex claims that 35 Chrome extensions with 4 million+ installs contain spyware or infostealer.
The accused extensions share code patterns, connect to common servers, and have similar system permissions.
Extensions often claim to perform ad blocking, extension protection, or privacy protection, but have minimal or missing code for their claimed purpose.
The identified extensions have obfuscated code and exhibit suspicious behavior, with some sending user data to web servers.