Microsoft recently removed 119 malicious extensions from the Edge Add-ons store. These extensions were disguising themselves as legitimate utilities like ad blockers and video downloaders to gain user trust and positive reviews before activating hidden payloads. Attackers used these extensions to steal sensitive login credentials, inject malicious advertisements into legitimate websites, and hijack online shopping links to steal commissions. To protect yourself, check your extensions against Microsoft’s published list of malicious add-ons, reset passwords for all critical accounts, and review your recent sign-in logs for unusual activity.