One of the most insidious and long-running cybercrime campaigns in recent years has been revealed, revealing how 17 malicious extensions managed to spread across Chrome, Firefox and Microsoft Edge. These extensions collectively recorded more than 840,000 downloads, seriously compromising the privacy and security of hundreds of thousands of users worldwide. The campaign, known as GhostPoster, emerged in 2020 and managed to remain active for up to five years, exploiting users’ trust in official extension stores.

Misleading names and a false sense of security
The creators of the malicious extensions used names that referred to popular and useful features, such as “Google Translate in Right Click,” “YouTube Download,” and “Ads Block Ultimate.” This made the extensions appear legitimate and harmless, dramatically increasing the chances of unsuspecting users installing them.
See also: Malicious Chrome extensions target enterprise HR platforms
The fact that these extensions were hosted in official stores further strengthened the illusion of reliability, revealing a fundamental weakness in the browser ecosystem: presence on an official platform is no guarantee of security.
How did they manage to go unnoticed?
One of the most disturbing aspects of the case is that the extensions successfully passed the automated security checks of major technology companies. This is due to a highly sophisticated mechanism for hiding malicious code, which made them significantly more difficult to detect during the initial scan.
Analysts point out that their long-term presence demonstrates both the effectiveness of the attack and how difficult it is for the average user to distinguish a dangerous extension from a legitimate one.

Steganography and hidden malicious code
The “technical heart” of the attack was based on steganography, a method in which malicious code is hidden inside seemingly harmless PNG image files. Once the extension is installed, it extracts the hidden payload and establishes communication with remote servers controlled by the attackers.
From there, additional malicious scripts are downloaded, which perform a series of harmful actions without the user even realizing it.
What they could do to victims' devices
The malware was exploited for multiple purposes: abusing affiliate links for financial gain, monitoring browsing behavior, modifying HTTP headers to disable security mechanisms, and stealing login credentials and personal data.
See also: TamperedChef: Malvertising campaign distributes malware via PDF manuals
The variety and complexity of these operations clearly shows that this is not an amateur or opportunistic attack, but an organized enterprise with a clear goal of profit and long-term access to user systems.
GhostPoster: Coordinated campaign across multiple platforms
The full picture of GhostPoster was revealed by researchers at LayerX Security, following the initial discovery of a suspicious Firefox extension by Koi Security. The investigation revealed common infrastructure, techniques, and connections between all 17 extensions, confirming that this is a single, coordinated campaign.

The attackers started with Edge and gradually expanded to Firefox and Chrome, each time adapting their code to comply with the different security policies of each platform.
See also: Hackers abuse legitimate cloud platforms to “host” phishing kits
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Delayed activation to avoid detection
Another particularly worrying feature was delayed execution. Extensions remained inactive for 48 hours or even up to five days after installation, thus fooling detection systems and making static analysis almost impossible.
The GhostPoster incident serves as a stark reminder that even the most “innocent” tools can harbor serious risks — and that user vigilance remains more necessary than ever.
