Yes, Chrome extensions can contain malware, but most don't — and you control which ones you install
A Chrome extension is code that runs inside your browser with access to everything you see and type. That makes extensions a real target for malware authors. An extension infected with a virus or spyware can steal passwords, track your browsing, inject ads into pages, or redirect your searches. But infection is not automatic — it happens when you install a malicious extension, usually because the listing looked legitimate or you didn't notice what permissions it was asking for.
The Chrome Web Store does scan extensions before they go live, but that scan is not foolproof. Bad actors regularly slip through with extensions that look harmless at first, then change their behavior after thousands of people have installed them. You are not helpless against this. Most of the risk comes down to three things: which extensions you choose, what permissions you grant them, and whether you notice when an extension's behavior changes.
Key Takeaways
- Chrome extensions run inside your browser with access to your passwords, browsing history, and anything you type, so a malicious one can steal sensitive information.
- The Chrome Web Store scans extensions before listing them, but scans miss malware regularly, especially extensions that change behavior after installation.
- Check the extension's permission request before you install it — if a weather app asks for access to all your browsing data, that is a red flag.
- Review your installed extensions regularly and remove any you no longer use or that you do not recognize.
- If an extension suddenly starts showing ads, changing your search engine, or behaving differently, uninstall it immediately.
What permissions an extension asks for and why that matters
When you install a Chrome extension, a popup shows you what it wants access to. This is your clearest warning sign. A legitimate weather extension should ask for your location — nothing else. A password manager needs access to your passwords and form data. A grammar checker needs to see the text you type. Anything beyond that is suspicious.
Some permissions are vague but necessary. "Access to all your data on all websites" sounds alarming, but a legitimate ad blocker or privacy tool genuinely needs it to work. The question is whether the extension's stated purpose matches what it is asking for. If you install a tool to convert currency and it asks for access to all your browsing history, uninstall it immediately. That extension is not doing what it claims.
You can see what permissions an extension has even after you install it. Go to chrome://extensions, find the extension, click Details, and scroll down to Permissions. If you see something you did not expect, remove the extension. You can also change permissions for individual sites — click the extension icon in your toolbar, then Details, then Site Access, and choose whether it can see data on all sites or only the ones you visit.
How to spot a malicious extension before you install it
The Chrome Web Store listing is your first defense. Look at the number of users and the rating. An extension with 50,000 users and a 4.8-star rating is lower risk than one with 12 users and a 5-star rating — the small one might be brand new, or the reviews might be fake. Read the actual reviews, not just the star count. Real users describe what the extension does and whether it works. Fake reviews often say generic things like "Great extension!" with no detail.
Check the developer's name and history. Click on the developer name to see their other extensions. If they have published dozens of extensions with similar names — like "PDF Reader Pro," "PDF Reader Plus," "PDF Reader Max" — that is a pattern used by malware authors who want to hide in a crowd. A legitimate developer usually publishes a small number of related tools.
Look at the description and screenshots. Does the extension do what you actually need? If you want to block ads and the listing shows screenshots of an ad blocker, that is good. If the screenshots show something unrelated to the description, or if the description is vague or full of typos, skip it. Legitimate developers spend time on their listings.
Why extensions change behavior after you install them
Some malicious extensions pass the Chrome Web Store scan because they behave normally at first. Days or weeks later, after thousands of people have installed them, the developer pushes an update that changes the extension's behavior. Suddenly it starts showing ads, redirecting your searches, or collecting your data. By then it is too late to stop the initial spread.
This happens because Chrome updates extensions automatically in the background. You do not see a notification that an extension has been updated unless you go looking for it. The extension just changes what it does, and you might not notice for weeks. This is why reviewing your extensions regularly matters — if an extension you trusted suddenly starts behaving strangely, you can remove it before it causes real damage.
Steps to check your installed extensions right now
Open a new tab and type chrome://extensions into the address bar. You will see a list of every extension you have installed, along with how many users each one has and its rating on the Chrome Web Store.
Go through the list and ask yourself: Do I recognize this extension? Do I still use it? If the answer to either question is no, click the trash icon to remove it. Pay special attention to extensions you do not remember installing — some come bundled with software you downloaded, or they were added by a browser hijacker.
For extensions you do use, click Details and check the permissions again. If an extension's permissions have changed since you installed it, that is a warning sign. Uninstall it and look for an alternative that does the same job with fewer permissions.
What to do if you think an extension has malware
If an extension starts showing ads you did not see before, changes your search engine without permission, or behaves in any way you did not expect, uninstall it immediately. Go to chrome://extensions, find the extension, and click the trash icon. The extension will be removed from your browser.
After you uninstall it, run a full scan with Windows Defender (on Windows) or Malwarebytes (on any system). A malicious extension might have installed other malware on your computer. Malwarebytes is free to download and run a scan, though it costs money for real-time protection. If the scan finds anything, let it remove it.
If the malicious extension had access to your passwords, change your passwords for important accounts — email, banking, social media. If it had access to your payment information, contact your bank or credit card company and let them know. Most credit cards have fraud protection, but notifying them early gives them a record of the incident.
Safer alternatives to risky extensions
The safest extension is no extension. Before you install one, ask whether Chrome's built-in features can do the job. Chrome has a built-in password manager, ad blocker (in some regions), and privacy controls. It can translate pages, read text aloud, and take screenshots. If you can do what you need without an extension, you eliminate the risk entirely.
If you do need an extension, choose one from a developer with a long history of published tools and thousands of users. Extensions from Google itself, like Google Translate or Google Dictionary, are safe — they are made by the company that controls Chrome. Extensions from well-known companies like Grammarly, LastPass, or Adblock Plus are lower risk because the company's reputation depends on not being malicious.
Read the permissions request carefully before you click Install. If an extension asks for more access than it needs to do its job, do not install it. There is almost always another extension that does the same thing with fewer permissions.
Frequently Asked Questions
Can a virus in a Chrome extension infect my whole computer?
A Chrome extension runs inside your browser, not at the system level, so it cannot directly install malware on your computer the way a downloaded file could. But a malicious extension can download and run other malware, so the risk is real. If you suspect an extension is malicious, uninstall it and run a full antivirus scan.
If I uninstall an extension, does it remove any malware it installed?
Uninstalling the extension removes the extension itself, but not necessarily any malware it downloaded. Run Malwarebytes or Windows Defender after you uninstall to check for other infections. If you had the extension for weeks before noticing something wrong, assume it had time to install other things.
Are extensions from the Chrome Web Store always safe?
The Chrome Web Store scans extensions before listing them, but the scan is not perfect. Malicious extensions slip through regularly, especially ones that behave normally at first and change later. The Web Store is safer than downloading extensions from random websites, but it is not a may provide.
What should I do if an extension asks for permission to access all my data?
Some legitimate extensions need broad access — ad blockers, privacy tools, and password managers all require it. Check whether the extension's purpose matches the permission. If a simple tool asks for access to all your data and it does not need it, uninstall it. You can also grant permission only on specific sites instead of all sites.
How often should I review my installed extensions?
Review your extensions at least once a month, or whenever you notice your browser behaving strangely. Remove anything you do not recognize or no longer use. If an extension you trust suddenly changes behavior, uninstall it immediately and check for other malware.