Chrome nukes top image-saving extension after it hijacked millions of shoppers
A browser add-on once praised in newsrooms from Madrid to Mexico City has turned into a million-user cookie-stuffing machine, Google admitted late Tuesday. The extension, marketed as a simple way to save WebP files as JPG or PNG, was silently rewriting affiliate links on at least 578 retail sites, siphoning commissions from purchases it had nothing to do with.
The hand-over that opened the door
Ownership shifted last August. Overnight the developer email switched from Image4Tools to an anonymous Gmail address, and the code followed suit. chrome’s Web Store scanners missed the payload; journalists and designers kept installing. By February Microsoft’s Edge team yanked the clone, but chrome’s version lingered until this week, when SafeBrowsing finally flashed red across every active install.
Google’s takedown notice is blunt: delete now, purge cookies, rotate passwords. The extension never needed your credentials; it only wanted your trail of clicks. Each shopping cart you filled became a tip jar for strangers.

One click, one commission stolen
Here’s how the scam worked. Visit any site — Nike, B&H, AliExpress — and the add-on injected its own affiliate tag into the URL. Checkout still looked normal to you, but the retailer recorded the sale under the extension’s account. Over a million daily users translated into thousands of skimmed dollars, every day, for seven months. No pop-ups, no slowdowns, just a quiet redirection masked as a format converter.
Spanish investigators traced the racket through server logs handed over by a Barcelona affiliate network. They found the same tag popping up in sessions traced to 63 countries, proof that geography is meaningless when the weapon is a browser.

Clean-up is manual and tedious
Uninstalling the extension stops future leaks, but the past is stickier. Cookies bearing the fake affiliate ID remain valid for up to 90 days on some programmes. Clear everything — cached images, site data, the lot — or the extension’s ghost keeps earning. chrome’s “reset settings” button does not touch third-party storage; you have to open the hood yourself.
Alternatives already fill the void. Save image as PNG and Image Converter both passed chrome’s latest security audit, though neither offers batch renaming. For newsrooms that process hundreds of files before lunch, that’s a feature gap worth watching. Expect a fresh wave of clones within days; the playbook is public now.
The takeaway? A utility that felt like a keyboard shortcut was actually a pickpocket with root access. Next time an extension promises to do one harmless thing, ask who gets paid when you press save.
