The Great Suspender Extension Attack
Updated 5 Oct 2026 · Incident date 1 Oct 2020 · browser extension
The Great Suspender 7.1.6/7.1.7 -> 7.1.8 (Chrome Web Store only)unnamed background/analytics script loading remote Java...The Great Suspender, a Chrome extension with about two million users, shipped version 7.1.8 in October 2020 with code that ran scripts from a remote server. The original developer had sold the extension in June 2020. Version 7.1.6 was the last release by the original owner.
Google removed it from the Chrome Web Store in February 2021 and disabled it for users.
What happened
In June 2020 the original developer sold the extension to an unknown entity, because he could not keep up with maintenance. BleepingComputer reports that the new owners released 7.1.8 in October 2020 with scripts that tracked user behavior and ran code from a remote server.
Version 7.1.8 went to the Chrome Web Store but not to GitHub, so the public source did not match. The GitHub issue reports that the extension loaded a script disguised as OpenWebAnalytics. Researchers said it intercepted requests, made extra advertising requests and used cookies. The script was heavily minified and obfuscated.
The script came from owebanalytics.com. According to the issue, that domain was created at the same time as the update, bought with Bitcoin, and held only tracking scripts.
The CNCF TAG Security catalog gives this timeline:
- 6 November 2020: a user found the malicious code
- 23 November 2020: Microsoft flagged the extension as malware
- Version 7.1.9 followed and removed the code
- 4 February 2021: the Chrome Web Store removed the extension, and Google disabled it
Affected versions
Version 7.1.8 is the malicious version, and it reached users through automatic store updates. Version 7.1.6 was the final release by the original developer and contains no malicious scripts, according to BleepingComputer.
- 7.1.6: clean, last release by the original owner
- 7.1.8: malicious, Chrome Web Store only
- 7.1.9: released after discovery, without the malicious code
The sources I fetched do not mention version 7.1.7.
Indicators of compromise
- Domain:
owebanalytics.com - Extension version 7.1.8 installed from the Chrome Web Store
- Extension source in the store that differs from the GitHub repository
How to check
Open chrome://extensions, turn on developer mode and read the version of The Great Suspender. You can also search the extension folder for the domain. This example is for Chrome on macOS.
grep -rl "owebanalytics" ~/Library/Application\ Support/Google/Chrome/*/Extensions
Also search DNS or proxy logs for owebanalytics.com.
What to do now
- Remove The Great Suspender from every browser.
- If you need your suspended tabs, use your browser history to find the URLs.
- Block
owebanalytics.com. - Treat the sites you used during the exposure as tracked. Change passwords for sensitive accounts.
- Use a different tab suspender from a source you trust.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 22 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED background.js It now downloads from the internet and runs other programs. It did not before.
Frequently asked questions
Which version of The Great Suspender was malicious?
Version 7.1.8, released in October 2020 on the Chrome Web Store. Version 7.1.6 was the last release by the original developer.
How did The Great Suspender become malware?
The original developer sold the extension in June 2020. The new owners released version 7.1.8 with code that loaded remote scripts from owebanalytics.com.
Sources
More supply chain attacks
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- Trust Wallet browser extension v2.68 compromise 24 Dec 2025
- RedDirection campaign (Color Picker Geco and 17 others) 27 Jun 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.