35-chrome-extensions-spying-on-you-right-now-yes-even-the-featured-ones-image-0

It’s 2026, and the Chrome Web Store still feels like a digital candy shop—except some of those colorful little extensions are actually poison-coated data thieves. Security researcher John Tuckner recently dropped a bombshell: at least 35 Chrome extensions, with a combined install base of over 4 million users, are quietly spying on everyone. And get this—ten of them proudly sport Google’s “Featured” badge. You know, the one that’s supposed to scream “Trust me, I’m verified!” 🤡

How did these wolves sneak into the sheepfold? Tuckner noticed they all share the same suspicious code patterns, connect to identical command-and-control servers, and demand an absurdly broad set of permissions. Most of them claim to do things like block ads, protect privacy, improve search results, or—wait for it—protect your browser from nasty extensions. The irony could power a small city. But when you peek under the hood, the code that would actually deliver those features is either laughably minimal or missing entirely. Instead, the real work is being done by obfuscated scripts designed to hide what’s really going on. Obfuscated code is the tech equivalent of a guy wearing a trench coat mumbling “nothing to see here.”

Here’s the kicker: 34 out of these 35 extensions are unlisted on the Chrome Web Store. That means they don’t appear in searches or regular browsing. So how did they rack up millions of installs? Did they fall off a truck? Were they promoted through sketchy ads or bundled with other software? The mystery remains, but the install counts don’t lie.

If you’re thinking, “Surely I’d recognize a rogue extension,” take a look at the full lineup. The names ooze trustworthiness—words like “Secure,” “Shield,” “Privacy,” and “Protecto” repeat like a broken record. The full rogue’s gallery includes gems such as:

  • Better Browse by SecurySearch

  • Bing Search by Securify

  • Browse Securely for Chrome (twice, because why not?)

  • Browser Checkup for Chrome by Doctor

  • Browser WatchDog for Chrome

  • Check My Permissions for Chrome

  • Choose Your Chrome Tools

  • Cuponomia - Coupon and Cashback

  • Data Shield for Chrome

  • Fire Shield Chrome Safety

  • Fire Shield Extension Protection

  • Global search for Chrome

  • In Site Search for Chrome

  • Incognito Search for Chrome

  • Incognito Shield for Chrome

  • Map Search for Chrome

  • MultiSearch for Chrome

  • News Search for Chrome

  • Privacy Guard for Chrome

  • Private Search for Chrome

  • Protecto for Chrome

  • Safe Search for Chrome

  • Securify Advanced Web Protection

  • Securify for Chrome

  • Securify Kid Protection

  • Securify Your Browser

  • SecuryBrowse for Chrome

  • Total Safety for Chrome

  • Unbiased Search by Protecto

  • Watch Tower Overview

  • Web Privacy Assistant

  • Web Results for Chrome

  • Website Safety for Chrome

  • Yahoo Search by Ghost

35-chrome-extensions-spying-on-you-right-now-yes-even-the-featured-ones-image-1

What do they actually do once installed? They ask for permissions that would make a firewall blush:

  • Tab management and interaction

  • Setting and storing browser cookies

  • Intercepting and modifying web requests

  • Storing data persistently in your browser

  • Injecting JavaScript into websites

  • Triggering system alerts

  • Interacting with browser activity while juggling other permissions

In other words, these extensions could be reading your emails, redirecting your searches, stealing session cookies, or silently injecting ads wherever they please. And because they all share the domain unknow.com in their background services (a domain that has zero legitimate purpose in the code), they’re tightly linked like a spy ring passing notes in class.

35-chrome-extensions-spying-on-you-right-now-yes-even-the-featured-ones-image-2

Should you scan your browser now? Absolutely. Even if you’re the kind of person who only installs extensions with five-star reviews and glowing testimonies, remember: malware authors are masters of social engineering. They know that slapping “Featured” on a tile instantly lowers your defenses. The fact that Google’s own verification process failed to catch this crew should serve as a wake-up call.

To be fair, Chrome does have security measures, and teams at Google work hard. But when 4 million installs and ten “Featured” badges slip through, it’s clear the vetting mechanism is more like a friendly nod than a background check. So what can you do? Uninstall any of the listed extensions immediately, audit your remaining extensions for excessive permission requests, and ask yourself: does my ad blocker really need access to my web requests and cookies, or is it just being nosy?

In a perfect world, every extension would be as pure as its description. But until then, keep your digital magnifying glass handy—and maybe think twice before granting “read and change all your data on all websites” to something called Total Safety for Chrome. Stay safe out there, and may your browser be ever free of spyware masquerading as a helpful toolbar. 🕵️‍♂️