On February 4, 2021, Google reached into people’s web browsers and forcibly removed a popular tool called The Great Suspender, classifying it as malware. Your web browser is the program you use to get on the internet, like Chrome, Edge or Safari. Malware is software built to spy on you or harm you. The tool had more than two million installs. It did one small, useful thing. It put tabs you weren’t using to sleep. Tabs are the open pages lined up across the top of your browser. When Google switched the tool off, the tabs it was holding got closed and were effectively lost.
How does a tab-sleeper end up as malware? Someone bought it.
Let’s back up. A tool like this is called a browser extension. It’s a small program you install inside your browser, a bit like an app on your phone. Think of it as a houseguest. You let it in because it promised to help. Then you forget it’s there.
I’m not saying every extension is a threat. Most aren’t. But the bad ones get the same access as the good ones, and you can’t tell them apart by looking at the little buttons at the top of your browser. So what exactly did those two million people hand over when they installed it? It came down to one small message that almost nobody reads.
When you install an extension, your browser often shows a message that says “Read and change all your data on the websites you visit.”
Most people click Allow. I don’t blame them. The message pops up at the exact moment you want the tool to work.
But read that sentence again. It means the extension can see every page you open. That includes your bank, your email and your medical records. It can also see what you type into them, like your passwords.
That’s a lot of trust to give a stranger. Most of us only feel comfortable doing it because we assume someone has checked. The store has a rating, the reviews are good, and thousands of people already use it. So surely it’s safe. That assumption is where things go wrong.
Most people think: “The store checks these things, and it has thousands of great reviews, it must be safe.”
That’s a fair thing to think. Here’s where it breaks down.
In June 2020, the creator of The Great Suspender sold it to an unknown buyer because he didn’t have time to keep maintaining it. Users were suspicious. Why would anyone pay for a free tool that earned no money? In October 2020, the new owner released an update with hidden instructions inside. They tracked what users did, and they could also run commands sent from a computer somewhere else. Microsoft removed the extension from its store. Google didn’t act until February 2021. That’s roughly eight months after the sale.
Nobody got a warning along the way. Browsers update your extensions automatically in the background. You never see it happen.
And this isn’t a one-off. The same pattern showed up at a much larger scale in 2025. On July 8, 2025, a security research firm called Koi Security reported an attack it named RedDirection. It involved 18 extensions on Chrome and Edge, reportedly reaching 2.3 million users. They were everyday tools like emoji keyboards, weather widgets and video speed controls. The color picker at the center of the case had been a legitimate tool for several years before a harmful update arrived. Some of these extensions even carried “Verified” and “Featured” badges from Google and Microsoft, essentially official stamps of approval.
Koi’s analyst said the harmful versions installed themselves silently, and most users never clicked anything.
That’s the problem with reviews and badges. They tell you who an extension was. They say nothing about who controls it next month.
So an extension can turn bad overnight, and nothing on your screen tells you. That raises the next question. Once it has turned, what can it actually do to you?
Here’s what it can do, starting with the quietest:
Watching: Quietly recording where you go and what you do online. The Great Suspender’s bad version tracked what users did.
Redirecting: Sending you somewhere you didn’t choose. Researchers said the RedDirection extensions tracked users, took over websites they were already signed in to, and sent their data to computers controlled by the attackers. Koi also warned that this kind of access could be used to send people to fake copies of their bank’s website and steal their logins.
Rewriting: Changing what a page shows you before you see it. This is the most unsettling one, so let me walk through how it could work. You send a friend $100. The extension quietly changes the amount to $1,000 and the destination to a thief’s account. Then it edits the confirmation page so it still says $100. This is an illustration of the mechanism, not a case I’m citing. It’s hard to catch because of how banks protect you. They secure the trip between your computer and theirs, like a sealed armored truck. They may also text you a one-time code to prove it’s really you. But the extension sits on your side. It changes things before they go into the truck and after they come out. The protections guard the trip, and the tampering happens on your screen.
Injecting ads: Slipping its own ads into pages you visit, or swapping out the ads that were already there, so someone else earns money from your browsing. After the first three, this one sounds minor. But it’s the most common. A study by Google and researchers at UC Berkeley and UC Santa Barbara found that over 5 percent of visits to Google’s own websites were altered this way. The data was from mid-2014. The researchers found 50,870 Chrome extensions and 34,407 installed programs doing it, and 38 percent of the extensions were classified as malware. That study is over a decade old. I don’t think the problem went away.
Notice what all four have in common. Every one of them depends on the extension being allowed to stay in your browser. Which means the fix isn’t finding the perfect tool. It’s getting much stricter about which ones you let stay.
You need a habit that security experts call Zero Trust. In plain terms: nothing is safe just because it was safe yesterday. Every extension has to keep earning its place.
Here’s how to put that into practice:
Open your browser’s extensions page today. If you haven’t used something in 90 days, remove it. Don’t just hide its button. Uninstall it.
Keep only the essentials running: A password manager (an app that stores your passwords safely) is a good example. Switch everything else off until the moment you need it.
Question the trade: For each one you keep, ask whether the permission matches the job. Does a note-taker or a page-color changer really need to read and change all your data on every site? If not, skip it.
Build a clean room for banking: Even after all that, some risk is left. So protect the places that matter most. Set up a separate browser profile, which is like a second, blank user account inside your browser. Install zero extensions in it. Use it only for banking, taxes and medical accounts. Also check that extensions are switched off in private or incognito windows, the ones that don’t save your browsing history. Is that overkill? Maybe, for some people. But I keep landing on the same answer. Banking is where a mistake costs the most, so that’s where to be strictest.
Remember, a five-star review tells you who the extension was. It can’t tell you who owns it tomorrow.
References
The Great Suspender (2020–2021)
BleepingComputer, “The Great Suspender Chrome extension’s fall from grace”: https://www.bleepingcomputer.com/news/security/the-great-suspender-chrome-extensions-fall-from-grace/
9to5Google, Feb 4, 2021: https://9to5google.com/2021/02/04/the-great-suspender-extension-has-been-removed-from-chrome-web-store-for-containing-malware/
The Hacker News, Feb 6, 2021: https://thehackernews.com/2021/02/warning-hugely-popular-great-suspender.html
RedDirection (2025)
Koi Security, original report, July 8, 2025: https://blog.koi.security/google-and-microsoft-trusted-them-2-3-million-users-installed-them-they-were-malware-fb4ed4f40ff5
SC Media (citing The Register): https://www.scworld.com/brief/millions-of-chrome-edge-users-compromised-with-malicious-extensions
Ad injection
Thomas et al., “Ad Injection at Scale: Assessing Deceptive Advertisement Modifications,” IEEE Symposium on Security and Privacy, 2015: https://people.cs.uchicago.edu/~grantho/papers/oakland2015_ad_injection.pdf
PCWorld, May 2015: https://www.pcworld.com/article/427356/superfish-injects-ads-in-one-in-25-google-page-views.html
