• Skip to main content
  • Skip to primary sidebar
  • Deals
  • Features
  • Guides
  • Chromebooks
  • Videos
  • Podcast
  • More +
    • Reviews
    • Unboxing
    • Upcoming Devices
    • Chromebook Plus
    • Chrome
    • ChromeOS
    • Chrome OS Flex
  • Search
  • Sign Up
  • Log In
Chrome Unboxed – The Latest Chrome OS News

Chrome Unboxed - The Latest Chrome OS News

A Space for All Things Chrome, Google, and More!

  • Deals
  • Features
  • Guides
  • Chromebooks
  • Videos
  • Podcast
  • More +
    • Reviews
    • Unboxing
    • Upcoming Devices
    • Chromebook Plus
    • Chrome
    • ChromeOS
    • Chrome OS Flex
  • Search
  • Sign Up
  • Log In

These 30 malicious Chrome extensions just showed their true colors, affecting millions

October 28, 2022 By Michael Perrigo View Comments

Support our independent tech coverage. Chrome Unboxed is written by real people, for real people—not search algorithms. Join Chrome Unboxed Plus for just $2 a month to get an ad-free experience, access to our private Discord, and more. Learn more about membership here.
START FREE TRIAL (MONTHLY)START FREE TRIAL (ANNUAL)

A new campaign of malicious Chrome extensions was just uncovered by a Guardio Labs research report called “Dormant Colors”. It’s a large campaign with 30 extensions and millions of active installations across the globe. You may or may not have installed one of these on your Chrome browser or Chromebook, so check out the list below! They are no longer active on either the Chrome or Edge web stores, but you should still uninstall them immediately! Also, the campaign itself remains fully active.

Source: Guardio

Each of these was built to change browser element colors and your theme and are essentially customization tools. Unfortunately, they weren’t pre-loaded with malicious code, and the hijacking was injected via a side loading method post-install.

Xremove ads

Once a user who had this on their device was targeted, it would steal their browser data including search history. Insert audible sigh here. I’m really getting wary of extensions when you see things like this happen. Even despite the seal of approval that Google added to the Web Store, side loading code later on in the user experience means they can effectively bypass the store itself, robbing us all of any peace of mind that the process of scanning and checking for bad actors provided, to begin with!

The catalog of the 30 extensions listed above rolled out just a few weeks ago for both Chrome and Edge and as you can see, they looked rather harmless and unsuspecting. The truth is that much of the code in these extensions was harmless, but provided a ‘dormant’ attack.

Featured Videos

Xremove ads

After being installed, the user would be redirected to another one of the extensions in the campaign and told they must install it before continuing. This is what’s called ‘malvertising’, and once the ‘Ok’ button is clicked, the individual is redirected to a blank ‘Thank you’ page loaded with malicious script.

To cut it short, this bad extension is much more than another search hijacker — it includes stealth modules for code updating and telemetry collection, as well as a backbone of servers harvesting data from millions of users, classifying potential targets, and being able to target specific users with many kinds of social engineering attack vectors that can quickly steal credentials and put people and even big organizations out of business!

Guardio Security Medium Blog

You can read all of the highly technical details on exactly how the script works over on Guardio’s blog post, but the end result is that the dormant code is activated, a list of 10,000 affiliate websites is injected, and any time you visit a website with a shopping list, you’re redirected through their affiliate link and they make money off of your back while stealing your privacy and data!

According to researchers, this campaign has the potential to do more than earn a few bucks on your purchases by appending affiliate links to the end of your shopping cart and could go on to create phishing pages for things like Google Workspace, bank website social media sites and more where it can directly steal your credentials for logging in.

Xremove ads

As a reminder, the malicious setup is still active and even though the extensions have been completely removed and can no longer be installed, code can still be sideloaded to those who have them on their systems, allowing these jerks to harm millions of users who remain unaware.

SUBSCRIBE TO UPSTREAM

Get Chrome Unboxed delivered straight to your inbox

Upstream is our flagship, curated newsletter with the top stories, most click-worthy deals, giveaways, and trending articles from Chrome Unboxed sent directly to your inbox a few times a week. Join 31,000+ subscribers.

SUBSCRIBE HERE!

Filed Under: Extensions, Privacy and Security

About Michael Perrigo

Known as "Google Mike" to his customers, Michael worked at Best Buy as a Chromebook Expert who dedicated his time to understanding the user experience from a regular Chromebook owner's perspective. Having spent nearly 20 years meeting you face-to-face, he strives to help you understand your technology through carefully crafted guides and coverage, relentlessly seeking out the spark in what's new and exciting about ChromeOS.

Primary Sidebar

Xremove ads

Deals

Pixel Buds Pro 2 running

I still love the Pixel Buds Pro 2 and they are $60 off right now

By Joseph Humphrey
March 13, 2026

The Lenovo Chromebook Slim 3 is the one to get, starting at just $139 right now

By Robby Payne
March 6, 2026

The best Chromebook deals today

By Robby Payne
March 6, 2026

The fantastic $599 deal on the Samsung Galaxy Chromebook Plus has returned

By Robby Payne
February 25, 2026

There are some great Pixel 10a pre-order offers right now: Here are my 2 favorite deals

By Joseph Humphrey
February 25, 2026

More Deals

Xremove ads

Reviews

Acer Chromebook Plus Spin 514 Review: Kompanio Ultra power in a convertible

By Robby Payne
December 24, 2025

My review after 6 weeks with the Lenovo Chromebook Plus 14 [VIDEO]

By Robby Payne
August 11, 2025

One week with the best small Android tablet you can buy, and I’m sold

By Robby Payne
May 9, 2025

Best Chromebooks of 2024 [VIDEO]

By Robby Payne
November 28, 2024

Samsung Galaxy Chromebook Plus Review: Samsung is back! [VIDEO]

By Robby Payne
October 28, 2024

More Reviews

Xremove ads

Guides

This Chromebook trackpad shortcut is definitely not new, but is blowing my mind

By Robby Payne
March 11, 2024

How to reduce broadcast delay on YouTube TV to stop live spoilers

By Robby Payne
December 8, 2023

Windows PC keyboard and Chromebook

How to use a Windows keyboard with a Chromebook

By Joseph Humphrey
December 8, 2023

How reset and revert your Chromebook to the previous version of Chrome OS

By Robby Payne
November 29, 2023

My Chromebook Plus features disappeared: here’s how I fixed it

By Robby Payne
November 24, 2023

More Guides

TWITTER · FACEBOOK · INSTAGRAM · YOUTUBE · EMAIL · ABOUT

Copyright © 2026 · Chrome Unboxed · Chrome is a registered trademark of Google Inc.
We are participants in various affiliate advertising programs designed to provide a means for us to earn fees by linking to affiliated sites.

PRIVACY POLICY