| This is a huge problem for the extension ecosystem in general. Who originally publishes an extension may not be the same entity that is pushing you updates in two years time, and there's no way as a user to know this. I publish a few extensions [1] [2] [3] and have been contacted multiple times by companies asking to buy them for several thousand dollars. They told me the going rate was 0.20 USD per user. You can imagine what kind of deals are being made when the extension has a million plus users. When pushed for exactly why they wanted to buy the extensions, which are in no way monetizable, they gave vague answers about "user insights". I can guarantee there will be many other major extensions that have sold out their users. [1] https://chrome.google.com/webstore/detail/old-reddit-redirec... [2] https://chrome.google.com/webstore/detail/break-timer/hklkdb... [3] https://chrome.google.com/webstore/detail/reddit-comment-col... |
Luckily enough the source code was still on github, and I managed to fork it and improve that version into "Tab Manager Plus" [1]
Since then I've refurbished around 10 extensions and published a few of my own. It's fun, just annoying that malicious extensions aren't getting taken down fast enough, since I suppose not enough people report them.
How to report malicious extensions is also sometimes unclear. Some people think they have to install them first, that's only true for ratings, not reports. For example to report the extension from this blog post you just have to submit this form [2]
For other malicious extensions simply replace the extension id in that link.
[1] Tab Manager Plus - https://chrome.google.com/webstore/detail/tab-manager-plus-f...
[2] Report extension - https://chrome.google.com/webstore/report/fjnbnpbmkenffdnngj...