2 min read

Researchers Discover Browser-Hijacking Google Chrome Extensions on Web Stores


October 25, 2022

Promo Protect all your devices, without slowing them down.
Free 30-day trial
Researchers Discover Browser-Hijacking Google Chrome Extensions on Web Stores

Researchers from Guardio Labs uncovered a new malicious campaign deploying rogue Google Chrome extensions that can hijack browsers. The threat actors push several derivatives of a color customization browser extension and keep them clean during the initial access phase to avoid detection.

Researchers dubbed the campaign “Dormant Colors” due to the nature of the extensions and their lack of malicious code when they’re installed on the target machines.

According to the Guardio Labs report, at least 30 variations of the extension were available for free on the Chrome and Edge web stores by mid-October, including:

  • Power Colors
  • Action Colors
  • Nino Colors
  • Background Colors
  • imginfo
  • hex colors
  • what color
  • Mega Colors
  • Mix Colors
  • Xer Colors
  • Dood Colors
  • More Styles

The report revealed that the rogue extensions had collectively gathered over 1 million installs. Perpetrators drove a malvertising campaign that altered users’ ability to download files or watch videos on certain websites. Upon landing on such a page, victims were urged to install an extension to access the content.

The malvertised extensions look harmless, as they hold no trace of malicious code. However, after installation, the rogue add-ons redirect users to web pages laced with malicious scripts that enable extensions to hijack browsers and insert affiliate links into webpages.

“This campaign is still up and running, shifting domains, generating new extensions, and re-inventing more color and style-changing functions you can for sure manage without,” reads Guardio Labs’ advisory. “Adding to that, the code injection technique analyzed here is a vast infrastructure for mitigation and evasion and allows leveraging the campaign to even more malicious activities in the future.”

Dedicated software such as Bitdefender Ultimate Security can protect you against malicious browser extensions and other cyberthreats thanks to its extensive list of features, including:

  • 24/7 real-time protection against worms, viruses, Trojans, rootkits, spyware, ransomware, zero-day exploits and other e-threats
  • Web filtering technology that prevents you from landing on suspicious or unsafe websites
  • Advanced threat defense system that monitors active apps and takes instant action upon detecting suspicious behavior
  • Network threat prevention module that scans, identifies and blocks suspicious network-level activities, including brute force attacks, bleeding-edge exploits and botnet-related URLs




Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.

View all posts

You might also like