The Chrome Extension Hijack Wave of 2024

Updated 5 Oct 2026 · Incident date 4 Jul 2024 · browser extension

Package16 Chrome extensions incl. Blipshot, Emojis - Emoji Keyboard, WAToolkit, Nimble Capture, KProxy, Adblock for Chrome, Super dark mode (malicious updates published Jul-Oct 2024)
Filebackground service worker

At least 16 Chrome extensions with more than 3.2 million users received malicious updates between July and October 2024. GitLab Threat Intelligence published the findings on 13 February 2025. The extensions include Blipshot, WAToolkit, Nimble Capture, KProxy, and several ad blockers.

GitLab found that the threat actor obtained access to at least some of the extensions from their original developers. The actor did not break into those accounts.

What happened

An unknown actor took control of 16 Chrome extensions and pushed updates that changed how they behaved. The GitLab report dates the malicious updates from 4 July to 8 October 2024.

Each extension sent its version and a hard-coded ID to a configuration server. The server then returned instructions. The extensions built rules that removed the Content Security Policy header from the first 2,000 websites visited in each session. They then injected remote JavaScript into pages through an iframe and a background tab.

GitLab thinks the actor delivers the malicious configuration only after a client has checked in many times, tracked on the server. This delay makes early testing find nothing. GitLab also found the injected scripts inside phishing kits that imitated McGill University in September 2024 and a Swiss railway site in late 2024. GitLab states that direct attribution is unclear.

Affected versions

GitLab lists the extensions by ID and does not publish one bad version number for all of them. The malicious updates were published between 4 July 2024 and 8 October 2024. In one example, Nimble Capture, the configuration contained the version string 12.0.0. Treat any installed copy of these extensions as affected.

ExtensionID
Blipshot: one click full page screenshotsmdaboflcmhejfihjcbmdiebgfchigjcf
Emojis - Emoji Keyboardgaoflciahikhligngeccdecgfjngejlh
WAToolkitfedimamkpgiemhacbdhkkaihgofncola
Color Changer for YouTubejlhgcomgldfapimdboelilfcipigkgik
Video Effects for YouTube And Audio Enhancerjdjldbengpgdcfkljfdmakdgmfpneldd
Themes for Chrome and YouTube Picture in Picturedeljjimclpnhngmikaiiodgggdniaooh
Mike Adblock für Chromegiaoehhefkmchjbbdnahgeppblbdejmj
Page Refreshhmooaemjmediafeacjplpbpenjnpcneg
Wistia Video Downloaderacbiaofoeebeinacmcknopaikmecdehl
Super dark modenlgphodeccebbcnkgmokeegopgpnjfkc
Emoji keyboard emojis for chromefbcgkphadgmbalmlklhbdagcicajenei
Adblocker for Chrome - NoAdsalplpnakfeabeiebipdmaenpmbgknjce
Adblock for Youogcaehilgakehloljjmajoempaflmdci
Adblock for Chromeonomjaelhagjjojbkcafidnepbfkpnee
Nimble capturebpconcjcammlapcogcnnelfmaeghhagj
KProxygdocgbfmddcfnlnpmnghmjicjognhonm

Indicators of compromise

GitLab lists these configuration and payload domains, one or more per extension:

Other indicators are a Content Security Policy header stripped from page loads and remote script injected into pages you did not expect to change.

How to check

Look for the extension IDs in your Chrome profile folder. This command works on macOS. On Linux, use ~/.config/google-chrome. On Windows, use %LOCALAPPDATA%\Google\Chrome\User Data.

ls ~/Library/Application\ Support/Google/Chrome/*/Extensions/ | grep -E 'mdaboflcmhejfihjcbmdiebgfchigjcf|gaoflciahikhligngeccdecgfjngejlh|fedimamkpgiemhacbdhkkaihgofncola|jlhgcomgldfapimdboelilfcipigkgik|jdjldbengpgdcfkljfdmakdgmfpneldd|deljjimclpnhngmikaiiodgggdniaooh|giaoehhefkmchjbbdnahgeppblbdejmj|hmooaemjmediafeacjplpbpenjnpcneg|acbiaofoeebeinacmcknopaikmecdehl|nlgphodeccebbcnkgmokeegopgpnjfkc|fbcgkphadgmbalmlklhbdagcicajenei|alplpnakfeabeiebipdmaenpmbgknjce|ogcaehilgakehloljjmajoempaflmdci|onomjaelhagjjojbkcafidnepbfkpnee|bpconcjcammlapcogcnnelfmaeghhagj|gdocgbfmddcfnlnpmnghmjicjognhonm'

You can also open chrome://extensions and compare each ID with the table above. Enterprise teams can search their extension inventory for the same IDs.

What to do now

  1. Remove every listed extension by hand. GitLab states that removal from the Chrome Web Store does not remove the extension from your browser.
  2. Change passwords for sites you used while an affected extension was active. The extensions could read and change page content.
  3. Block the listed domains at your DNS or proxy and search logs for them.
  4. Review the host_permissions of the extensions you keep.
  5. Restrict which extensions staff can install. Watch for ownership changes and new permissions in the extensions you rely on.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old 16-prev --new 16-current
files scanned: 25

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    background.js
           It now downloads from the internet and restarts itself after a reboot. It did not before.

Frequently asked questions

Which Chrome extensions were hijacked in the 2024 wave?

GitLab lists 16 extensions, including Blipshot, Emojis - Emoji Keyboard, WAToolkit, Color Changer for YouTube, Page Refresh, Wistia Video Downloader, Super dark mode, several Adblock for Chrome variants, Nimble Capture, and KProxy.

Does removing a hijacked extension from the Chrome Web Store uninstall it?

No. GitLab states that removal from the store does not trigger an automatic uninstall, so you must remove the extension by hand.

How many users did the extension hijack wave affect?

GitLab reports more than 3.2 million users across the 16 extensions.

Sources

  1. gitlab-com.gitlab.io/gl-security/security-tech-notes/threat-intelligence-tech-notes/malicious-browser-extensions-feb-2025/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free