Microsoft Removes 119 Malicious Edge Extensions for Credential Theft and Ad Fraud
Microsoft has shut down a long-running malicious‑extension campaign in its Edge Add‑ons store, naming the operation “StegoAd.” The campaign used steganography to embed executable JavaScript inside ordinary image (PNG, WebP) and font (WOFF2) files, allowing the payload to evade static scanners. The hidden code remained dormant for three to five days and performed checks for developer tools before activating, which let the extensions stay on the store for years.
A total of 119 extensions – ranging from ad blockers and VPNs to translators and video downloaders – were identified. Combined, they were installed up to 2.6 million times. The payloads performed two main functions: credential theft and ad fraud. They stole Google account passwords and second‑factor codes, harvested WordPress admin logins, exfiltrated session cookies, and injected malicious advertisements or affiliate‑link hijacking on sites such as Amazon, eBay and AliExpress. Some variants also delivered a remote‑code‑execution backdoor that could load additional malware from command‑and‑control servers operating behind Cloudflare Workers and GitHub Pages.
Microsoft removed all 119 extensions, suspended more than 90 developer accounts, and published indicators of compromise for Edge, Chrome and Firefox. Users are advised to review installed extensions via edge://extensions, delete any that match the published list, change passwords for Google, WordPress and other sensitive services, and enable strong two‑factor authentication or hardware security keys.