Browser extensions get stolen. A useful extension changes hands to a new developer, an update ships malware, or a popular extension is sold and quietly repurposed. This has happened to major extensions repeatedly. If you suspect one of yours has gone bad, here is a calm, ordered response verified against current extension and browser behaviors in August 2026.

The two-minute check: is this a real compromise?
Before you panic, ask yourself:
- Did a known extension suddenly change behaviour? New ads, unexpected redirects, or a changed search engine are the most common signs.
- Did an extension update recently? Check
chrome://extensions/(or your browser's extension page) and look at the "Last updated" date. - Have you read reports of a compromise? Search the extension's name plus "bought" or "compromised" or "malware" to see if others have reported problems.
If none of these apply, the issue may be a browser setting or a different extension. If one or more apply, proceed with the full response.
Step 1: Isolate and document
- Do not close the browser yet. If you close it, you may lose forensic data. Instead, open a new browser (or use a different browser entirely) to look up recovery steps.
- Document what you see. Screenshot the extension's permission page, the change log, and any suspicious behaviour. This helps later if you need to report the extension.
- Note the extension's store URL. You will need this to report it to the store.
Step 2: Disable and remove the extension
- Go to
chrome://extensions/(or the equivalent in your browser:edge://extensions/,about:addonsin Firefox). - Disable the suspicious extension first, rather than deleting it immediately. This stops the threat while preserving the extension for investigation.
- If you are sure it is compromised, delete it. Remove it from all browsers where it was installed.
- Check for other extensions that may have been installed by the same developer or at the same time. Remove anything you do not recognise.
Step 3: Rotate credentials
The most dangerous thing a compromised extension can do is steal passwords. If the extension had "read all data on all websites" permission, assume it could have captured anything you typed:
- Start with your email account. Change the password and enable two-factor authentication. Your email is the master key to your other accounts.
- Change passwords for your most important accounts first: banking, social media, work logins, and any site that stores payment details.
- If you use a password manager, change its master password and review recent logins.
- Enable two-factor authentication on every account that offers it. Our two-factor authentication guide covers the setup.
Step 4: Check for data exposure
- Review your email for password reset messages you did not request. These can mean someone tried to access your accounts using stolen credentials.
- Check your bank and credit card statements for unusual charges, starting with small transactions (scammers test stolen cards with small amounts).
- Run a security scan on your device with your antivirus or a dedicated malware removal tool.
Step 5: Report the extension
- Chrome Web Store: use the "Report abuse" link on the extension's store page.
- Firefox Add-ons: use the "Report this add-on" link.
- Edge Add-ons: use the "Report abuse" link.
- File a complaint with the FTC and the FBI IC3 if you lost money or sensitive data.
One-time cleanup
- Clear your browser cache and cookies for the period the extension was active. This removes any injected scripts or persistent tracking it may have left behind.
- Review your browser's saved passwords and remove any that were saved while the extension was active.
- Check for changes to your browser settings — home page, search engine, new tab page — and restore them.
The honest note about prevention
The best defense against a compromised extension is not having many extensions. The few you keep should be from developers you can verify, and you should review them periodically. Our how to choose safe browser extensions guide covers the vetting process, and extension permissions explained breaks down what each permission actually means. Most compromises happen silently, and the less software you give broad access to, the smaller your exposure.
Quick answers
How do I know if an extension has been compromised? New ads, unexpected redirects, a changed search engine, or a sudden change in behaviour after an update are the most common signs.
What should I do first? Disable the extension (do not delete it yet), document what you see, and change passwords starting with your email account.
Can a compromised extension steal my passwords? If it had "read all data on all websites" permission, yes — it could have captured anything you typed. Change your passwords and enable two-factor authentication.
Should I report the extension? Yes — report it through the store's abuse link and file a complaint with the FTC and IC3 if you lost money or data.
Sources and further reading
Written by Hassan Arshad, founder of UsefulOrbit. Last updated August 31, 2026. Response plan verified against current extension and browser behaviours, August 2026.