A browser extension that's allowed to run on steamcommunity.com works inside your signed-in Steam session. It can read the pages you see and act on them the way you would, and for a trader that includes inventories and trade offers. Most extensions are harmless, but the documented cases below show how the bad ones have hurt Steam users, and what to check before you install anything.
Why extensions matter for a Steam account
Google's own help page sets out the scale of access. An extension with access to "your data on all the websites you visit" can read, request or modify data on every page you open. Google adds that the warning doesn't mean an extension is dangerous, only that it could be.
On Steam, those pages include your inventory and trade offers, which Valve lets you create and send from a web browser. You still have to confirm every offer that sends items out, and Valve says there's no way to opt out of that. But Valve's guidance on trade redirection shows why that isn't the end of it: someone with access to your account or computer can cancel a trade you're expecting and replace it with a near-identical one to an account they control, hoping you approve it without reading.
That's why Valve's checklist for a suspected compromise doesn't stop at passwords. It tells you to scan for malware and check for malicious applications and web extensions.
Documented cases
2016: trade helpers that sent items to their author
In January 2016, Engadget reported that security researchers had caught a known scammer offering Chrome extensions that claimed to change your CS:GO theme or help you gamble with skins. Once installed, they did nothing except steal items from the victim's Steam inventory. By the time Engadget wrote its story the extensions appeared to have been pulled and the scammer's Steam account had been banned from trading. Removing the extension was enough to stop it.
2017: a popular inventory extension starts watching
In September 2017, gHacks reported that an update to a popular Chrome extension for managing, trading, buying and selling Steam items had added a monitoring component. The new code ran on every page load and tracked where you came from, when you arrived and left, mouse movement and key presses (though not what you typed), and it sent the links you clicked and a summary of web requests to a server.
The change was spotted because the update asked for a new permission to "read and change all your data on the websites you visit". Chrome disables an updated extension until you accept a new permission like that, which made the permission prompt the warning sign.
2018: one flaw, every signed-in site
In June 2018, a security researcher disclosed a pair of vulnerabilities in version 1.13.6 of the same extension. Because it had permission to run on all websites, he showed, a malicious page could exploit the flaws to hijack every site the victim was signed in to, from Steam to their bank or email. His demonstration lured the victim with a fake "bot detection" page asking them to paste a "verification code". The developers fixed it three days after his report. The lesson: broad permissions turn an ordinary bug into a threat to every account you use.
2024 to 2026: poisoned updates and session theft
The wider extension world shows the same patterns at scale. In April 2026, Bitdefender reported research by Socket into 108 malicious Chrome extensions disguised as Telegram helpers, games and video tools, with about 20,000 installs between them, that stole Google account details and copied Telegram Web sessions every 15 seconds. The same article recalled Christmas 2024, when a phishing email gave attackers access to a security company's Chrome Web Store account and let them push a poisoned update; Bitdefender said the wider campaign compromised more than 35 extensions used by an estimated 2.6 million people.
| Year | What happened | The lesson |
|---|---|---|
| 2016 | Fake trade helpers stole inventory items | An extension can act as you on Steam |
| 2017 | An update added browsing monitoring | Read the permission prompt on updates |
| 2018 | A bug in an all-sites extension exposed every signed-in account | Broad access magnifies honest mistakes |
| 2024–2026 | Hijacked updates and session-stealing extensions in the official store | The store badge isn't a guarantee |

How to vet an extension before installing
- Ask whether it needs Steam at all. A price overlay or inventory tool needs Steam's pages; a theme or a coupon finder doesn't. Chrome lets you narrow an extension's site access to "when you select the extension", to specific sites, or to all sites, under the extension's Details page.
- Read the warning level. Google rates access to all your data on all websites as a medium alert, and access to everything on your computer and the sites you visit as a high alert.
- Stop at new permission requests. An update that suddenly wants wider access is exactly how the 2017 case came to light. Don't accept it until you know why.
- Use Chrome's Enhanced Safe Browsing. With it on, Chrome warns you when an extension comes from a developer it doesn't yet trust. Google says new developers generally take a few months to earn that status.
- Install from the store yourself. Valve warns never to download and run a program suggested by someone in chat. Treat an extension a trade partner, "admin" or giveaway sends you the same way.
- Never paste codes or keys into an extension. No legitimate tool needs your Steam Guard codes, and Valve says your Steam Web API key should never be shared.
- Keep fewer. Bitdefender's advice after the 2026 case was to remove extensions you don't use and question whether each one's permissions fit what it does.

If you think an extension has turned
Remove it from your browser first. Then work through Valve's steps for a compromised account: review Authorized Devices and use Sign out everywhere, change your Steam password from a device you trust, check your email account, and scan for malware. Open steamcommunity.com/dev/apikey and revoke any key you didn't create; our API key scam guide explains why.
Check your Trade History as well. CS2 items that left in trades during the last seven days can be pulled back with a reversal under trade protection, at the cost of a 30-day trading and Market cooldown. Our account security checklist covers the habits worth keeping afterwards.
Sources
- Chrome gaming add-ons steal your Steam inventory — Engadget
- Steam Inventory Helper monitors your browsing activity — gHacks
- Steam, Fire, and Paste: a story of UXSS via DOM-XSS and clickjacking in Steam Inventory Helper — The Hacker Blog
- 108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users — Bitdefender
- Permissions requested by apps and extensions — Chrome Web Store Help
- Install and manage extensions — Chrome Web Store Help
- Account Security Recommendations — Steam Support
- Scam: Trade Redirection — Steam Support



