← Back to feed
AwarenessEmerging1 sourceSep 17, 2026 · 20:18via Kaspersky Blog

Malicious Chrome and Edge add-ons: how to spot them and why they’re dangerous | Kaspersky official blog

Brief

Malicious extensions and ClickFix attacks are two hugely popular topics on our blog, and for a good reason: they’re both very common. In this post, we bring them together. Here’s the thing: in our posts about malicious ClickFix instructions, we don’t always explain exactly how users end up on the attackers’ pages in the first place.

A recent study gives us a chance to fill that gap and talk about one of those methods: malicious extensions.

Readers who are not deep into cybersecurity may already have a bunch of questions at this point: how can extensions be malicious? where do they come from? and what exactly is ClickFix, anyway? Fret not: this post answers all these questions.

The danger of browser extensions

Let’s start with the basics. Browser extensions or add-ons are lightweight tools installed in your browser to give it extra capabilities or change how it works with web pages.

Read more on Kaspersky Blog