Malicious browser extensions and Steam: documented cases and how to vet one

An extension that runs on Steam's pages works inside your signed-in session. Documented cases from 2016 to 2026, what extension permissions mean, and a checklist before you install one.

A browser extension that's allowed to run on steamcommunity.com works inside your signed-in Steam session. It can read the pages you see and act on them the way you would, and for a trader that includes inventories and trade offers. Most extensions are harmless, but the documented cases below show how the bad ones have hurt Steam users, and what to check before you install anything.

Why extensions matter for a Steam account

Google's own help page sets out the scale of access. An extension with access to "your data on all the websites you visit" can read, request or modify data on every page you open. Google adds that the warning doesn't mean an extension is dangerous, only that it could be.

On Steam, those pages include your inventory and trade offers, which Valve lets you create and send from a web browser. You still have to confirm every offer that sends items out, and Valve says there's no way to opt out of that. But Valve's guidance on trade redirection shows why that isn't the end of it: someone with access to your account or computer can cancel a trade you're expecting and replace it with a near-identical one to an account they control, hoping you approve it without reading.

That's why Valve's checklist for a suspected compromise doesn't stop at passwords. It tells you to scan for malware and check for malicious applications and web extensions.

Documented cases

2016: trade helpers that sent items to their author

In January 2016, Engadget reported that security researchers had caught a known scammer offering Chrome extensions that claimed to change your CS:GO theme or help you gamble with skins. Once installed, they did nothing except steal items from the victim's Steam inventory. By the time Engadget wrote its story the extensions appeared to have been pulled and the scammer's Steam account had been banned from trading. Removing the extension was enough to stop it.

2017: a popular inventory extension starts watching

In September 2017, gHacks reported that an update to a popular Chrome extension for managing, trading, buying and selling Steam items had added a monitoring component. The new code ran on every page load and tracked where you came from, when you arrived and left, mouse movement and key presses (though not what you typed), and it sent the links you clicked and a summary of web requests to a server.

The change was spotted because the update asked for a new permission to "read and change all your data on the websites you visit". Chrome disables an updated extension until you accept a new permission like that, which made the permission prompt the warning sign.

2018: one flaw, every signed-in site

In June 2018, a security researcher disclosed a pair of vulnerabilities in version 1.13.6 of the same extension. Because it had permission to run on all websites, he showed, a malicious page could exploit the flaws to hijack every site the victim was signed in to, from Steam to their bank or email. His demonstration lured the victim with a fake "bot detection" page asking them to paste a "verification code". The developers fixed it three days after his report. The lesson: broad permissions turn an ordinary bug into a threat to every account you use.

2024 to 2026: poisoned updates and session theft

The wider extension world shows the same patterns at scale. In April 2026, Bitdefender reported research by Socket into 108 malicious Chrome extensions disguised as Telegram helpers, games and video tools, with about 20,000 installs between them, that stole Google account details and copied Telegram Web sessions every 15 seconds. The same article recalled Christmas 2024, when a phishing email gave attackers access to a security company's Chrome Web Store account and let them push a poisoned update; Bitdefender said the wider campaign compromised more than 35 extensions used by an estimated 2.6 million people.

YearWhat happenedThe lesson
2016Fake trade helpers stole inventory itemsAn extension can act as you on Steam
2017An update added browsing monitoringRead the permission prompt on updates
2018A bug in an all-sites extension exposed every signed-in accountBroad access magnifies honest mistakes
2024–2026Hijacked updates and session-stealing extensions in the official storeThe store badge isn't a guarantee
An extension with access to Steam's pages works inside your signed-in session
An extension with access to Steam's pages works inside your signed-in session

How to vet an extension before installing

  • Ask whether it needs Steam at all. A price overlay or inventory tool needs Steam's pages; a theme or a coupon finder doesn't. Chrome lets you narrow an extension's site access to "when you select the extension", to specific sites, or to all sites, under the extension's Details page.
  • Read the warning level. Google rates access to all your data on all websites as a medium alert, and access to everything on your computer and the sites you visit as a high alert.
  • Stop at new permission requests. An update that suddenly wants wider access is exactly how the 2017 case came to light. Don't accept it until you know why.
  • Use Chrome's Enhanced Safe Browsing. With it on, Chrome warns you when an extension comes from a developer it doesn't yet trust. Google says new developers generally take a few months to earn that status.
  • Install from the store yourself. Valve warns never to download and run a program suggested by someone in chat. Treat an extension a trade partner, "admin" or giveaway sends you the same way.
  • Never paste codes or keys into an extension. No legitimate tool needs your Steam Guard codes, and Valve says your Steam Web API key should never be shared.
  • Keep fewer. Bitdefender's advice after the 2026 case was to remove extensions you don't use and question whether each one's permissions fit what it does.
Offers built in the browser still need your confirmation in the Steam Mobile app, so read every one
Offers built in the browser still need your confirmation in the Steam Mobile app, so read every one

If you think an extension has turned

Remove it from your browser first. Then work through Valve's steps for a compromised account: review Authorized Devices and use Sign out everywhere, change your Steam password from a device you trust, check your email account, and scan for malware. Open steamcommunity.com/dev/apikey and revoke any key you didn't create; our API key scam guide explains why.

Check your Trade History as well. CS2 items that left in trades during the last seven days can be pulled back with a reversal under trade protection, at the cost of a 30-day trading and Market cooldown. Our account security checklist covers the habits worth keeping afterwards.

Sources

More in Security

All Security articles