Protect.Computer
NEWS

119 malicious Edge extensions caught stealing your passwords

· 1 min read · Got hacked Malicious byte
119 malicious Edge extensions caught stealing your passwords

Microsoft has quietly removed 119 browser extensions from its Edge store after finding they were secretly stealing passwords and hijacking user accounts. The campaign, called StegoAd by researchers, was unusually sneaky: the malware wasn’t hidden inside the extension code itself — it was embedded in PNG images, WebP files, and WOFF2 font files using a technique called steganography, which hides executable instructions inside ordinary-looking files. The extensions posed as everyday tools including ad blockers, VPNs, translators, and video downloaders.

Once installed, these extensions could steal your Google login credentials, WordPress admin passwords, and session cookies — giving attackers the ability to take over your accounts without even needing your current password. They also ran ad fraud behind the scenes, silently redirecting shopping commissions on Amazon, eBay, and AliExpress purchases away from you to the attackers. Up to 2.6 million users may have had one of these extensions installed.

How to check if you’re affected

Affected versions of Microsoft Edge include any version where one of the 119 removed extensions was installed before Microsoft pulled them from the store.

  • Check your extensions: in Microsoft Edge, go to edge://extensions and look for anything unfamiliar — especially ad blockers, VPNs, translators, or video download tools you don’t clearly remember installing.
  • Remove suspicious extensions immediately and restart the browser.
  • If you used Edge with any questionable extension in the past few months, treat your passwords as compromised: change your Google account password, any WordPress admin passwords, and any other accounts you accessed through that browser.
  • Enable two-factor authentication on Google and any other important account — even a stolen password won’t be enough to log in if 2FA is active.
  • Review sign-in activity in your Google account at myaccount.google.com/security to check for any logins you don’t recognize.

Sources

Related reading