The Add to Feedly Extension Sold to an Adware Operator
Updated 5 Oct 2026 · Incident date 1 Jan 2014 · browser extension
Add to Feedly (Chrome, ~30,000 users) - clean release by Amit Agarwal, then an adware update by the new ownernot documented - no filename or version number was ever...The Add to Feedly Chrome extension had more than 30,000 users when its author sold it. The new owners then pushed an update that replaced links on every site with affiliate links.
The sources do not give a version number or file name for the bad update.
What happened
The author sold the extension, and the buyer used a store update to add hidden ads. Amit Agarwal, who wrote the extension, says on Labnol that he made it in about one hour. An unknown buyer contacted him by email and paid a four-figure sum through PayPal. He could not verify who the buyer was. InfoWorld reports that the sale took place in late 2013.
The update added advertising. Labnol quotes it as inserting adware into all web pages. The Register describes invisible ads that work in the background and turn links on every site into affiliate links. Users could opt out, but that was not the default. Labnol says the update targeted superfish.com domains. Extension ratings dropped in the Chrome store. After media coverage, Google removed the extension from the store.
The same group of articles covers a second extension, Tweet This Page. InfoWorld reports it sold for 500 US dollars at the end of November 2013 and was also turned into adware. The Register adds that Google tightened its store terms in December 2013 and had warned developers in October 2013. Read Labnol, The Register and InfoWorld.
This case needs no stolen password. The store account changed hands, and the update came from the new owner. The extension gained code that runs against every page it sees. For a case with a stolen developer login, see Web Developer for Chrome.
Affected versions
The sources do not name an extension version. The affected product is the Add to Feedly extension for Chrome, with more than 30,000 users at the time of the sale. The bad update was live in January 2014, and Google removed the extension that month after the story spread.
How to check
Check whether the extension is still installed. List the names of extensions in your Chrome profile. This command works on macOS.
grep -H '"name"' ~/Library/Application\ Support/Google/Chrome/Default/Extensions/*/*/manifest.json
On Linux, use ~/.config/google-chrome/Default/Extensions. You can also open chrome://extensions and look for Add to Feedly. Some names show as message keys. If a name is not clear, open the extension page for details. The sources list no file indicators for this attack.
What to do now
- Remove Add to Feedly from Chrome if it is still installed.
- Use the Feedly bookmarklet, as the author recommends on Labnol.
- Check the other extensions you use. Remove those you do not need.
- If you own an extension, do not sell it to a buyer you cannot verify. Users cannot see the change of owner.
- Review the permissions of each extension before you accept an update.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 31 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE background.js It downloads from the internet.
Frequently asked questions
What happened to the Add to Feedly Chrome extension?
The author sold it, and the new owners updated it to inject invisible ads that turned links on every site into affiliate links. Google then removed it from the store.
How many users did the Add to Feedly extension have?
More than 30,000 users when it was sold.
How do I check if I still have the Add to Feedly extension?
Open chrome://extensions and look for Add to Feedly, or list the manifest names in your Chrome Extensions folder.
Sources
More supply chain attacks
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- Trust Wallet browser extension v2.68 compromise 24 Dec 2025
- RedDirection campaign (Color Picker Geco and 17 others) 27 Jun 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.