<!--DEBUG:--><!--DEBUG:dc3-united-states-software-in-english-pdf-2--><!--DEBUG:--><!--DEBUG:dc3-united-states-software-in-english-pdf-2--><!--DEBUG-spv-->{"id":3448195,"date":"2026-01-25T15:39:55","date_gmt":"2026-01-25T13:39:55","guid":{"rendered":"http:\/\/nhub.news\/?p=3448195"},"modified":"2026-01-26T00:17:21","modified_gmt":"2026-01-25T22:17:21","slug":"using-browser-extensions-to-translate-or-download-videos-better-check-for-these-17-malicious-add-ons","status":"publish","type":"post","link":"http:\/\/nhub.news\/ru\/2026\/01\/using-browser-extensions-to-translate-or-download-videos-better-check-for-these-17-malicious-add-ons\/","title":{"rendered":"Using Browser Extensions to Translate or Download Videos? Better Check for These 17 Malicious Add-Ons"},"content":{"rendered":"<p style=\"text-align: justify;\"><b>The most popular malicious extension, dubbed Google Translate in Right Click, was downloaded more than 500,000 times from app stores. Another, Translate Selected Text with Google, racked up almost 160,000 downloads.<\/b><br \/>\nIf you\u2019ve been using browser extensions to download YouTube videos or images from Pinterest, translate text in real time, check Amazon price histories, or even enhance colors, you might have some uninstalling to do.<br \/>Cybersecurity firm LayerX has uncovered 17 malicious browser extensions that were downloaded more than 840,000 times in total, with some remaining active in the wild for up to five years. Instances were recorded across Firefox, Google Chrome, and Microsoft Edge browsers.<br \/>Mozilla and Microsoft have removed all of the extensions from their official stores at the time of writing. However, if you\u2019ve already installed one, you\u2019ll need to uninstall it manually.<br \/>The most popular malicious extension, dubbed \u201cGoogle Translate in Right Click,\u201d was downloaded more than 500,000 times from app stores. Another, \u201cTranslate Selected Text with Google,\u201d racked up almost 160,000 downloads.<br \/>The extensions were part of a malware campaign researchers named GhostPoster, identified by Koi Security last month. The browser-based malware used \u201csteganography\u201d\u2014hidden links or code embedded inside images\u2014to infiltrate users\u2019 machines.<br \/>The extensions also relied on a technique known as delayed execution, meaning it could take weeks or even months before their malicious behavior was triggered. Once activated, the extensions were capable of stripping and injecting HTTP headers to weaken web security policies, hijacking affiliate traffic for monetization, and injecting scripts to enable click fraud and user tracking.<br \/>In addition, the extensions could perform automated CAPTCHA solving and inject additional malicious scripts, giving attackers extended control over infected browsers.<br \/>The extensions were named: Google Translate in Right Click, Translate Selected Text with Google, One Key Translate, Translate Selected Text with Right Click, Ads Block Ultimate, AdBlocker, Amazon Price History, Color Enhancer, Cool Cursor, Convert Everything, RSS Feed, and Floating Player \u2013 PiP Mode.<br \/>Others listed include: YouTube Download, Instagram Downloader, Save Image to Pinterest on Right Click, Full Page Screenshot, Page Screenshot Clipper, and Youtube Download.<br \/>But these aren\u2019t the only extensions you need to worry about. Koi\u2019s earlier investigation unveiled numerous other malicious browser extensions, including the popular Urban VPN Proxy, a Google Chrome extension with 8 million users that was secretly collecting data from conversations with AI tools like ChatGPT, Claude, and Gemini to sell to data brokers.<br \/>The illicit VPN used the same strategy of hiding code inside a PNG image before redirecting the user to a website primed to inject malware.<br \/>If one of the extensions above looks familiar, check out PCMag\u2019s guide to removing browser extensions from most major browsers.<\/p>\n<script>jQuery(function(){jQuery(\".vc_icon_element-icon\").css(\"top\", \"0px\");});<\/script><script>jQuery(function(){jQuery(\"#td_post_ranks\").css(\"height\", \"10px\");});<\/script><script>jQuery(function(){jQuery(\".td-post-content\").find(\"p\").find(\"img\").hide();});<\/script>","protected":false},"excerpt":{"rendered":"<p>The most popular malicious extension, dubbed Google Translate in Right Click, was downloaded more than 500,000 times from app stores. Another, Translate Selected Text with Google, racked up almost 160,000 downloads. If you\u2019ve been using browser extensions to download YouTube videos or images from Pinterest, translate text in real time, check Amazon price histories, or [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3448192,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[93],"tags":[],"_links":{"self":[{"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/posts\/3448195"}],"collection":[{"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/comments?post=3448195"}],"version-history":[{"count":1,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/posts\/3448195\/revisions"}],"predecessor-version":[{"id":3448198,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/posts\/3448195\/revisions\/3448198"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/media\/3448192"}],"wp:attachment":[{"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/media?parent=3448195"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/categories?post=3448195"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/tags?post=3448195"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}