This is a public service announcement that everyone should be careful when installing extensions from the Chrome Web Store. While most extensions are perfectly harmless, it is starting to become more and more common for unwanted and malicious extensions to be uploaded to the store and not be removed for quite a while.
For example, today I was told about a new Chrome extension called
Image Downloader (this link will hopefully be down soon) that Aura, one of our malware removal helpers, thought looked suspicious. On closer examination, this extension is adware as it injects advertisements into web sites that you are visiting, opens unwanted sites in new tabs when you interact with the site, and injects advertisements into the top of search engine result pages.
You can see a video illustrating how this extension works below.
....
.......
.....
...........
When the browser starts, the extension will connect to two sites to download configuration information that is needed to operate properly. This information will then be used by the extension to inject ads as shown below.
Injected Advertisements