# Microsoft removes 119 Edge extensions hiding malware in images and

**Published:** 2026-06-29T19:39:25.422Z  
**Topic:** Microsoft  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/e1f1145e-3afa-4d82-bc21-92c4a56c9ceb

Microsoft pulled 119 malicious Edge add‑ons used steganography to hide code in images and fonts, affecting up to 2.6 million users.

Microsoft removed 119 Edge browser extensions that concealed malware inside image and font files, a campaign Microsoft labels “StegoAd” and ties to a single threat actor active since at least 2021 [1]. The takedown eliminates a potential attack surface for up to 2.6 million users and underscores the difficulty of spotting steganographic payloads in popular add‑ons.

| At a glance | |
|---|---|
| Extensions removed | 119 |
| Max install base | 2.6 million users |
| Threat actor activity | Since 2021 |
| Malware delivery method | Steganography in PNG, WebP, WOFF2 files |

## How the extensions worked  
The extensions—ranging from ad blockers and VPNs to translators and video downloaders—functioned normally and earned positive reviews, allowing them to linger in the Edge Add‑ons store for years. Each carried dormant malicious code that activated only after passing a series of evasion checks, a delay that let the payload “wake up” days after install [1]. Early variants appended JavaScript after the IEND marker of a PNG icon; later versions switched to WebP images and WOFF2 font files, embedding code in glyph ranges that appear as Asian text or font metadata. Microsoft notes that such large‑scale steganography is rare in the browser‑extension ecosystem [1].

## Impact and scope  
The hidden payloads served two primary goals. First, they injected ads and hijacked affiliate links on sites such as Amazon, eBay and AliExpress, generating illicit revenue for the operators. Second, they stole credentials—including Google passwords, two‑factor codes, and WordPress admin logins—and exfiltrated cookies for session hijacking [1]. Microsoft’s analysis also found seven Google Analytics IDs used as covert telemetry, giving the actor near‑real‑time visibility into the campaign [1]. The operation employed more than ten command‑and‑control domains, leveraged Cloudflare Workers and GitHub Pages for hosting, and migrated from Manifest V2 to V3 as Edge evolved [1].

## Market reaction  
Microsoft’s removal of the extensions coincided with a modest dip in its stock price on the day of the announcement [2]. While the share movement reflects investor sensitivity to security incidents, the broader impact is limited to Edge users, as the extensions have now been taken down and the 90‑plus developer accounts behind them suspended [1]. The episode highlights the ongoing challenge for browser stores to vet add‑ons that appear benign but embed malicious code in non‑executable assets.

## What to watch
- **Extension audit rollout** – Microsoft may expand its review process for Edge add‑ons, potentially affecting future developer submissions.  
- **Threat actor activity** – Indicators of compromise released by Microsoft could surface in other Chromium browsers, signaling whether the campaign migrates elsewhere.  
- **Edge market share** – Any shift in user confidence could influence Edge’s adoption relative to Chrome and Firefox in the coming quarters.

The removal of the 119 StegoAd extensions removes a sizable covert attack vector, but the actor’s infrastructure and use of common asset types suggest the technique could reappear in other browsers or future extensions, keeping the security community on alert.

## Sources
1. Thehackernews — [Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts](https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html)
2. Tipranks — [Microsoft Stock (NASDAQ:MSFT) Slips After Pulling 119 Edge Extensions - TipRanks.com](https://www.tipranks.com/news/microsoft-stock-nasdaqmsft-slips-after-pulling-119-edge-extensions)
3. Technadu — [Microsoft Removes 119 StegoAd Edge Extensions Hiding Malware - TechNadu](https://www.technadu.com/microsoft-removes-over-100-stegoad-edge-extensions-hiding-malware-via-steganography/630058/)

---
Cite as: TrendWatcher, "Microsoft removes 119 Edge extensions hiding malware in images and", https://www.trendwatcher.in/article/e1f1145e-3afa-4d82-bc21-92c4a56c9ceb
