The RedDirection Browser Extension Attack

Updated 5 Oct 2026 · Incident date 27 Jun 2025 · browser extension

PackageColor Picker, Eyedropper - Geco colorpick (Chrome) plus 17 Chrome/Edge extensions incl. Emoji keyboard online, Free Weather Forecast, Video Speed Controller, Volume Max, Unblock TikTok
Filebackground service worker using chrome.tabs.onUpdated.addListener

RedDirection was a campaign of 18 Chrome and Edge extensions, including Color Picker, Eyedropper - Geco colorpick, that turned malicious through store updates. Koi Security disclosed it in July 2025 and reported 2.3 million affected users.

The extensions had been clean for years and some carried a verified badge. A later update added code that sent each visited URL to an attacker server and could redirect the browser.

What happened

The extensions started as legitimate tools. After years of normal use, malicious versions arrived as automatic store updates. The Register quotes the researcher saying the versions installed silently for more than 2.3 million users across both browsers.

eSentire describes the behavior. The extensions watch all open tabs. They send each URL to a remote command server with a unique tracking ID. The command server can then tell the browser to go to a different address.

The register of the story: Microsoft removed the extensions from its store and disabled them for Edge users. Google had not responded when The Register published.

The code that gained this power sat in each extension's background service worker, which listens for tab updates.

Affected versions

The campaign covers 18 extensions. eSentire lists these Chrome extension IDs.

The Register also names Edge extensions: TikTok Unlocker, Volume Booster, Web Sound Equalizer, Header Value, Flash Player Emulator, YouTube Unblocked, SearchGPT and Discord Unlocker. The sources I fetched do not give the exact bad version numbers.

Indicators of compromise

eSentire lists these domains. Look for them in DNS and proxy logs.

How to check

Open the extensions page in each browser and compare the IDs with the list above. In Chrome, go to chrome://extensions. In Edge, go to edge://extensions.

You can also search the local extension folders for an ID. This example checks Chrome on macOS.

ls ~/Library/Application\ Support/Google/Chrome/*/Extensions | grep -E "eokjikchkppnkdipbiggnmlkahcdkikp|kgmeffmlnkfnjpgmdndccklfigfhajen|gaiceihehajjahakcglkhmdbbdclbnlf"

To look for the domains, search the extension files.

grep -rl "admitclick.net" ~/Library/Application\ Support/Google/Chrome/*/Extensions

What to do now

  1. Remove the affected extensions from Chrome and Edge.
  2. Clear browser data and reset browser settings, as eSentire advises.
  3. Reset credentials for accounts used on the affected browsers and watch them for odd activity.
  4. Block the listed domains at your DNS or proxy.
  5. Review the other extensions you have installed for similar behavior, and tell staff about the risk of third-party tools.

A verified badge does not show that an update is safe. Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Color-prev --new Color-current
files scanned: 64

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    background.js
           It now downloads from the internet and restarts itself after a reboot. It did not before.

Frequently asked questions

What is the RedDirection campaign?

RedDirection is a July 2025 campaign in which 18 Chrome and Edge extensions turned malicious through updates. They sent visited URLs to attacker servers and could redirect the browser. Koi Security reported 2.3 million affected users.

How do I check if I have a RedDirection extension?

Open chrome://extensions or edge://extensions and compare the extension IDs with the list published by eSentire. Remove any match.

Sources

  1. theregister.com/2025/07/08/browser_hijacking_campaign/
  2. esentire.com/security-advisories/reddirection-browser-extension-campaign

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free