How to handle fake browser extensions that steal credentials
Cybercriminals keep refining the ways they reach into Australian households, and malicious browser add-ons have become one of the quieter threats on the radar of the Australian Cyber Security Centre. Unlike noisy ransomware, these rogue extensions sit in the background of Chrome, Firefox or Edge and quietly siphon login details as users type them. A single compromised add-on can expose banking portals, cloud email and any other service accessed from the same browser session.
These fake tools often impersonate productivity helpers, coupon finders, ad blockers or AI assistants. Once installed, they request broad permissions that let them read form fields, scrape autofill data and forward anything useful to a remote server. Many victims in Sydney and Melbourne only realise something is wrong when unexplained transfers appear in their CBA, ANZ, Westpac or NAB accounts, or when their myGov and ATO portals start behaving oddly.
The guidance below walks through how these threats arrive, the warning signs to watch for, a clean removal process, and the everyday habits that reduce the chance of being caught again.
How rogue browser extensions reach your system
Most malicious add-ons do not arrive through the official Chrome Web Store or Mozilla Add-ons page alone. Attackers rely on a few well-worn delivery paths. Software bundles packaged with free utilities are still common, particularly when Australians download PDF converters or video tools from unfamiliar sites. Sponsored search ads that mimic legitimate downloads are another favourite, as are hijacked extensions that began life as genuine projects before being sold to a new maintainer.
Phishing is just as relevant. An email posing as a notice from the ATO about a tax refund, or a message that appears to come from a Telstra or Optus account manager, may push recipients to install a "security" or "verification" add-on. Once the user agrees, the malicious code piggybacks on the browser with the same trust level as any legitimate plugin.
A growing number of cases now involve so-called "session hijackers" that piggyback on already-installed extensions after a drive-by compromise. Australians who travel frequently and use hotel, airport or café Wi-Fi across the NBN-connected country are particularly exposed, because the same laptop is reused on untrusted networks before returning home.
Warning signs that an add-on is harvesting credentials
Symptoms of a rogue extension are easy to overlook at first. The browser may feel slightly slower, web pages may take longer to render, and unfamiliar icons may appear next to the address bar. Some users notice that searches are being rerouted through an unknown search engine, or that their default homepage has quietly changed overnight.
More telling signals involve the actual login process. If a banking site suddenly looks visually different, asks for extra details, or produces a captcha that did not appear the day before, that can point to a man-in-the-browser layer inserted by the extension. Watch for unexpected two-factor prompts on services that never asked for them before, especially across major Australian platforms such as myGov, big-four bank portals and ATO online services.
Behind the scenes, an extension may be exporting saved passwords, autofill data and the contents of form fields to an attacker-controlled server. Unusual outbound traffic from the browser, sudden battery drain on a laptop, or unexpected spikes in mobile data when tethering can be subtle hints that something is calling home far too often.
Removing the fake extension safely
Start by listing every extension currently installed in each browser you have. In Chrome, the menu path leads through Extensions under More Tools; in Firefox it sits under Add-ons and Themes; in Edge it lives under Extensions. Anything unfamiliar, anything with vague permissions, or anything you do not remember installing should be disabled first and removed second.
After the browser is clean, run a full system scan because most credential-stealing extensions arrive alongside other malware. A companion keylogger removal guide walks through deeper inspection when you suspect keystrokes are also being recorded. Resetting the browser to its default state and clearing cookies, site data and saved passwords closes the door on any session tokens the rogue add-on may have captured.
Reinstall only the add-ons you genuinely need, and download them directly from the official store rather than from third-party catalogues. If a banking session was open during the infection window, contact the institution directly using a number printed on the back of your card, not one found through the browser.
Comparing browser security postures
Not every browser handles rogue extensions the same way. The table below compares the four most common choices for Australian households across several security-relevant criteria.
| Feature |
Chrome |
Firefox |
Edge |
Brave |
| Extension permission prompts |
Yes |
Yes |
Yes |
Yes |
| Built-in phishing protection |
Yes |
Yes |
Yes |
Yes |
| Sandboxed extension processes |
Yes |
Yes |
Yes |
Yes |
| Synchronised password manager |
Yes |
Yes (lockwise) |
Yes |
Limited |
| Easy extension review audit |
Moderate |
Good |
Good |
Moderate |
Even with strong defaults, no browser is immune to a malicious add-on that the user installs willingly. The biggest swing factor remains how clearly permission scopes are explained and how easy it is for a non-technical user in Brisbane, Adelaide or Perth to audit what is installed.
Habits that keep your credentials out of reach
Recovery is only half the job. The other half is making sure the same pattern cannot happen again. For users on Windows machines, broader system-level cleanup resources are available for Windows and cover prevention as well as post-incident steps that go beyond the browser itself.
A few steady habits reduce the risk of falling for a rogue add-on again.
- Install extensions only from the official store, and check the developer name, number of users and last update date before clicking Add.
- Review extension permissions every few months and remove anything unused, especially after reading news about a specific add-on being sold or compromised.
- Use a password manager so saved credentials are not exposed if a browser is compromised, and turn on multi-factor authentication for myGov, banking and email accounts.
- Keep your operating system and browser updated, since updates often patch the very flaws that extension-based attacks rely on.
- Report any suspected credential theft to your bank, to the ACSC via ReportCyber, and to the Office of the Australian Information Commissioner if personal data is exposed under the Notifiable Data Breaches scheme.