A widespread browser hijacking campaign has infected over 2.3 million users through 18 malicious extensions available on Google Chrome and Microsoft Edge.Among the extensions identified, “Color Picker, Eyedropper Geco colorpick” stood out with more than 100,000 installs, over 800 positive reviews, and verified status in the Chrome Web Store. Despite its legitimate appearance and functional user interface, the extension was found to be capturing browsing activity and sending data to remote servers.Other extensions offered varied functionality — from emoji keyboards and weather forecasts to VPN proxies, dark themes, and volume boosters but all contained similar surveillance and hijacking capabilities hidden in their code. Do you think that all extensions should be blocked ?

