Researchers from the American security firm ICEBRG have identified four Chrome extensions that contained malicious code. All four extensions were available through the Chrome Web Store.
According to the researchers, the four Chrome extensions were designed to allow attackers to send malicious commands to users' browsers in the form of JavaScript. 
The attackers used this capability to perform click fraud by loading a page in the background that contained advertisements.
The names of the four extensions are:
Change HTTP Request Header (ppmibgfeefcglejjlpeihfdimbkfbbnm), Nyoogle – Custom Logo for Google (ginfoagmgomhccdaclfbbbhfjgmphkph), Lite Bookmarks (mpneoicaochhlckfkackiigepakdgapj), and Stickies – Chrome's Post-it Notes (djffibmpaakodnbmcdemmmjmeolcmbae).
Of the four, Nyoogle is still available in the Chrome Web Store, as of this writing.
The extensions have been downloaded more than 500,000 times by users of Google's browser. When ICEBRG researchers detected the malicious behavior of the add-ons, they notified the Dutch National Cyber Security Center (NCSC-NL) and the US-CERT.
While three of the four extensions were immediately removed from the Chrome Web Store, many Chrome users still use them in their browsers.
The company published a detailed report on the extensions' malicious behavior in the hope that users will take some time to check their browser and remove the malicious extensions from their computers.
