The RedDirection Browser Extension Attack
Updated 5 Oct 2026 · Incident date 27 Jun 2025 · browser extension
Color Picker, Eyedropper - Geco colorpick (Chrome) plus 17 Chrome/Edge extensions incl. Emoji keyboard online, Free Weather Forecast, Video Speed Controller, Volume Max, Unblock TikTokbackground service worker using chrome.tabs.onUpdated.addListenerRedDirection was a campaign of 18 Chrome and Edge extensions, including Color Picker, Eyedropper - Geco colorpick, that turned malicious through store updates. Koi Security disclosed it in July 2025 and reported 2.3 million affected users.
The extensions had been clean for years and some carried a verified badge. A later update added code that sent each visited URL to an attacker server and could redirect the browser.
What happened
The extensions started as legitimate tools. After years of normal use, malicious versions arrived as automatic store updates. The Register quotes the researcher saying the versions installed silently for more than 2.3 million users across both browsers.
eSentire describes the behavior. The extensions watch all open tabs. They send each URL to a remote command server with a unique tracking ID. The command server can then tell the browser to go to a different address.
The register of the story: Microsoft removed the extensions from its store and disabled them for Edge users. Google had not responded when The Register published.
The code that gained this power sat in each extension's background service worker, which listens for tab updates.
Affected versions
The campaign covers 18 extensions. eSentire lists these Chrome extension IDs.
- Emoji keyboard online:
kgmeffmlnkfnjpgmdndccklfigfhajen - Free Weather Forecast:
dpdibkjjgbaadnnjhkmmnenkmbnhpobj - Video Speed Controller:
gaiceihehajjahakcglkhmdbbdclbnlf - Unlock Discord VPN Proxy:
mlgbkfnjdmaoldgagamcnommbbnhfnhf - Dark Theme:
eckokfcjbjbgjifpcbdmengnabecdakp - Volume Max:
mgbhdehiapbjamfgekfpebmhmnmcmemg - Unblock TikTok:
cbajickflblmpjodnjoldpiicfmecmif - Unlock YouTube VPN:
pdbfcnhlobhoahcamoefbfodpmklgmjm - Color Picker (Geco colorpick):
eokjikchkppnkdipbiggnmlkahcdkikp - Weather:
ihbiedpeaicgipncdnnkikeehnjiddck
The Register also names Edge extensions: TikTok Unlocker, Volume Booster, Web Sound Equalizer, Header Value, Flash Player Emulator, YouTube Unblocked, SearchGPT and Discord Unlocker. The sources I fetched do not give the exact bad version numbers.
Indicators of compromise
eSentire lists these domains. Look for them in DNS and proxy logs.
admitab.comedmitab.comclick.videocontrolls.comc.undiscord.comclick.darktheme.netc.jermikro.comc.untwitter.comc.unyoutube.netadmitclick.netaddmitad.comadmiitad.comabmitab.comadmitlink.net
How to check
Open the extensions page in each browser and compare the IDs with the list above. In Chrome, go to chrome://extensions. In Edge, go to edge://extensions.
You can also search the local extension folders for an ID. This example checks Chrome on macOS.
ls ~/Library/Application\ Support/Google/Chrome/*/Extensions | grep -E "eokjikchkppnkdipbiggnmlkahcdkikp|kgmeffmlnkfnjpgmdndccklfigfhajen|gaiceihehajjahakcglkhmdbbdclbnlf"
To look for the domains, search the extension files.
grep -rl "admitclick.net" ~/Library/Application\ Support/Google/Chrome/*/Extensions
What to do now
- Remove the affected extensions from Chrome and Edge.
- Clear browser data and reset browser settings, as eSentire advises.
- Reset credentials for accounts used on the affected browsers and watch them for odd activity.
- Block the listed domains at your DNS or proxy.
- Review the other extensions you have installed for similar behavior, and tell staff about the risk of third-party tools.
A verified badge does not show that an update is safe. Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 64 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED background.js It now downloads from the internet and restarts itself after a reboot. It did not before.
Frequently asked questions
What is the RedDirection campaign?
RedDirection is a July 2025 campaign in which 18 Chrome and Edge extensions turned malicious through updates. They sent visited URLs to attacker servers and could redirect the browser. Koi Security reported 2.3 million affected users.
How do I check if I have a RedDirection extension?
Open chrome://extensions or edge://extensions and compare the extension IDs with the list published by eSentire. Remove any match.
Sources
More supply chain attacks
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- Trust Wallet browser extension v2.68 compromise 24 Dec 2025
- Cyberhaven Chrome extension compromise 25 Dec 2024
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.