Researchers find Chrome extensions that hijack affiliate links and scrape data

by

Security researchers uncovered malicious Google Chrome extensions in January 2026 that hijack affiliate links, scrape product data, and exfiltrate information. The activity includes a cluster of 29 add ons that automatically replace affiliate tags on e commerce sites.

KEY FACTS

  • Incident Extensions modify affiliate links and divert commissions
  • Scope A cluster of 29 add ons targets multiple e commerce platforms
  • Technique URL rewriting and data scraping with remote exfiltration
  • Policy Behavior conflicts with Chrome Web Store affiliate and single purpose rules

A technical analysis by Socket reported that an extension called Amazon Ads Blocker was uploaded to the Chrome Web Store on January 19, 2026 and that its code injects the developer affiliate tag “10xprofit-20” into Amazon product links.

The report shows the extension is part of a larger cluster of 29 browser add ons that target platforms including AliExpress, Amazon, Best Buy, Shein, Shopify, and Walmart. The add ons search for existing affiliate tags and either replace them or append the attacker tag when none is present.

The report also documents that some extensions scrape product details and send the data to a remote endpoint hosted at app.10xprofit.io. Certain add ons present fake countdown timers on product pages to create a false sense of urgency.

The report notes that extension listings made misleading disclosures about commissions and that the combined functions violate the Chrome Web Store requirement for accurate disclosure and single purpose design, since ad blocking was combined with automatic affiliate injection.

WHY IT MATTERS

Browser extensions run with broad access to web content, making them an attractive vector to divert revenue and harvest data. Users and administrators should review installed extensions and remove or replace unknown or unnecessary add ons.