The Chrome Extension Hijack Wave of 2024
Updated 5 Oct 2026 · Incident date 4 Jul 2024 · browser extension
16 Chrome extensions incl. Blipshot, Emojis - Emoji Keyboard, WAToolkit, Nimble Capture, KProxy, Adblock for Chrome, Super dark mode (malicious updates published Jul-Oct 2024)background service workerAt least 16 Chrome extensions with more than 3.2 million users received malicious updates between July and October 2024. GitLab Threat Intelligence published the findings on 13 February 2025. The extensions include Blipshot, WAToolkit, Nimble Capture, KProxy, and several ad blockers.
GitLab found that the threat actor obtained access to at least some of the extensions from their original developers. The actor did not break into those accounts.
What happened
An unknown actor took control of 16 Chrome extensions and pushed updates that changed how they behaved. The GitLab report dates the malicious updates from 4 July to 8 October 2024.
Each extension sent its version and a hard-coded ID to a configuration server. The server then returned instructions. The extensions built rules that removed the Content Security Policy header from the first 2,000 websites visited in each session. They then injected remote JavaScript into pages through an iframe and a background tab.
GitLab thinks the actor delivers the malicious configuration only after a client has checked in many times, tracked on the server. This delay makes early testing find nothing. GitLab also found the injected scripts inside phishing kits that imitated McGill University in September 2024 and a Swiss railway site in late 2024. GitLab states that direct attribution is unclear.
Affected versions
GitLab lists the extensions by ID and does not publish one bad version number for all of them. The malicious updates were published between 4 July 2024 and 8 October 2024. In one example, Nimble Capture, the configuration contained the version string 12.0.0. Treat any installed copy of these extensions as affected.
| Extension | ID |
|---|---|
| Blipshot: one click full page screenshots | mdaboflcmhejfihjcbmdiebgfchigjcf |
| Emojis - Emoji Keyboard | gaoflciahikhligngeccdecgfjngejlh |
| WAToolkit | fedimamkpgiemhacbdhkkaihgofncola |
| Color Changer for YouTube | jlhgcomgldfapimdboelilfcipigkgik |
| Video Effects for YouTube And Audio Enhancer | jdjldbengpgdcfkljfdmakdgmfpneldd |
| Themes for Chrome and YouTube Picture in Picture | deljjimclpnhngmikaiiodgggdniaooh |
| Mike Adblock für Chrome | giaoehhefkmchjbbdnahgeppblbdejmj |
| Page Refresh | hmooaemjmediafeacjplpbpenjnpcneg |
| Wistia Video Downloader | acbiaofoeebeinacmcknopaikmecdehl |
| Super dark mode | nlgphodeccebbcnkgmokeegopgpnjfkc |
| Emoji keyboard emojis for chrome | fbcgkphadgmbalmlklhbdagcicajenei |
| Adblocker for Chrome - NoAds | alplpnakfeabeiebipdmaenpmbgknjce |
| Adblock for You | ogcaehilgakehloljjmajoempaflmdci |
| Adblock for Chrome | onomjaelhagjjojbkcafidnepbfkpnee |
| Nimble capture | bpconcjcammlapcogcnnelfmaeghhagj |
| KProxy | gdocgbfmddcfnlnpmnghmjicjognhonm |
Indicators of compromise
GitLab lists these configuration and payload domains, one or more per extension:
blipshotextension.comemojikeyboardextension.comwatoolkit.comcolorchanger.netytvideoeffectsextension.comthemesforytextension.comadblockforytextension.compagerefresh-extension.comwistiaextension.comsdmextension.comemojikeyboardforchrome.comnoadsadblocker.comabu-xt.comabfc-extension.comnimblecapture.comkproxyservers.site
Other indicators are a Content Security Policy header stripped from page loads and remote script injected into pages you did not expect to change.
How to check
Look for the extension IDs in your Chrome profile folder. This command works on macOS. On Linux, use ~/.config/google-chrome. On Windows, use %LOCALAPPDATA%\Google\Chrome\User Data.
ls ~/Library/Application\ Support/Google/Chrome/*/Extensions/ | grep -E 'mdaboflcmhejfihjcbmdiebgfchigjcf|gaoflciahikhligngeccdecgfjngejlh|fedimamkpgiemhacbdhkkaihgofncola|jlhgcomgldfapimdboelilfcipigkgik|jdjldbengpgdcfkljfdmakdgmfpneldd|deljjimclpnhngmikaiiodgggdniaooh|giaoehhefkmchjbbdnahgeppblbdejmj|hmooaemjmediafeacjplpbpenjnpcneg|acbiaofoeebeinacmcknopaikmecdehl|nlgphodeccebbcnkgmokeegopgpnjfkc|fbcgkphadgmbalmlklhbdagcicajenei|alplpnakfeabeiebipdmaenpmbgknjce|ogcaehilgakehloljjmajoempaflmdci|onomjaelhagjjojbkcafidnepbfkpnee|bpconcjcammlapcogcnnelfmaeghhagj|gdocgbfmddcfnlnpmnghmjicjognhonm'
You can also open chrome://extensions and compare each ID with the table above. Enterprise teams can search their extension inventory for the same IDs.
What to do now
- Remove every listed extension by hand. GitLab states that removal from the Chrome Web Store does not remove the extension from your browser.
- Change passwords for sites you used while an affected extension was active. The extensions could read and change page content.
- Block the listed domains at your DNS or proxy and search logs for them.
- Review the
host_permissionsof the extensions you keep. - Restrict which extensions staff can install. Watch for ownership changes and new permissions in the extensions you rely on.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 25 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED background.js It now downloads from the internet and restarts itself after a reboot. It did not before.
Frequently asked questions
Which Chrome extensions were hijacked in the 2024 wave?
GitLab lists 16 extensions, including Blipshot, Emojis - Emoji Keyboard, WAToolkit, Color Changer for YouTube, Page Refresh, Wistia Video Downloader, Super dark mode, several Adblock for Chrome variants, Nimble Capture, and KProxy.
Does removing a hijacked extension from the Chrome Web Store uninstall it?
No. GitLab states that removal from the store does not trigger an automatic uninstall, so you must remove the extension by hand.
How many users did the extension hijack wave affect?
GitLab reports more than 3.2 million users across the 16 extensions.
Sources
More supply chain attacks
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- Trust Wallet browser extension v2.68 compromise 24 Dec 2025
- RedDirection campaign (Color Picker Geco and 17 others) 27 Jun 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.