02/09/2026
The extension you installed last year is not the one running today
You review which packages your developers install. Then you give a browser extension read access to every authenticated tab you have, with two clicks and no review. And you will never see the code it runs tomorrow.

There is a genre doing the rounds on social media right now: "seven browser extensions everyone in security needs." The lists are usually fine. The tools exist, and they do what they say.
The advice is still backwards, and it is worth understanding why.
A browser extension is not a program you run alongside your browser. It runs inside it, with your permissions, on your tabs. Ask for access to all sites — and most useful ones do — and it can read everything you can see. The accounting system. The client list. The invoices. Your logged-in session with your cloud provider.
It is the most privileged software most people install, and the only kind they install without thinking.
What makes it different
You probably review which packages your developers pull in. You ask vendors for a data processing agreement. You have opinions about who gets access to what.
Then you click "Add" in a browser store and hand over more than any of them have.
And here is what separates extensions from everything else you install: you consent once, but the code is replaced forever. Extensions update themselves, quietly, in the background. You approved the developer, not the code. If the extension changes hands — or the developer's account is taken over — the new code arrives on your machine without you doing anything, and without a signal.
That is not a theoretical possibility. It is how the actual attacks have worked.
Three cases worth knowing
At Christmas 2024, the security company Cyberhaven was hit. A phishing email gave an attacker access to their developer account in the browser store, and from there an update was published that harvested cookies and session tokens. Auto-update pushed it to roughly 400,000 users. The company found it and pulled it within an hour — but the same actors had taken over 30 other extensions, with 2.6 million users between them.
Note what Cyberhaven sells: tooling against data loss. It was their own extension that leaked.
In January 2026, Socket found five coordinated extensions going specifically after Workday, NetSuite and SAP SuccessFactors. They exfiltrated session cookies — in some cases every sixty seconds, so the tokens stayed fresh — while manipulating pages to block the very admin surfaces where someone might have noticed.
The extensions had roughly 2,300 installs. That is a small number, and that is the point: this was not a broad attack. It was a precise one, aimed at the systems holding the personnel data.
In February that year, LayerX described the campaign they call AiFrame: 32 extensions posing as ChatGPT, Gemini and DeepSeek, installed around 260,000 times. They injected hidden iframes into every page you visited, carrying content the attacker controlled.
That campaign is still running. New extensions appear as the old ones are removed — the most recent batch included a fake two-factor authentication app.
What I actually think you should do
Not stop using extensions. Nobody follows that advice, and they shouldn't — the tools are useful.
But separate your browsers. Keep one profile where you are logged into what matters: accounting, banking, the cloud, the customer system. You install nothing there. Keep another profile, or another machine, for tools, testing, and anything you found in a reel. The two are never the same.
It takes five minutes to set up and costs you nothing day to day.
Then do the dull part as well: go through the extensions you already have. Don't ask whether you trust them. Ask whether you remember installing them, and whether you still know who owns them.
The point behind this
We spend a lot of effort assessing vendors who send us a contract, and almost none on the ones that just ask for a click.
That is not because the click is harmless. It is because nobody sends you an invoice for it.
Next time someone shows you a list of tools you should install, ask one question first: where is this going to run? The answer is almost never "in the browser where I'm logged into everything."

Roger Agerup
Founder and AI advisor