Popular Chrome extension “Save image as Type” pulled after reported link‑hijack and data collection
Removal follows discovery of suspicious code
A widely used browser extension, “Save image as Type”, has been removed from Google (谷歌) Chrome’s Web Store after it was reportedly found to contain malicious code. The tool — long a top pick for users wanting to save web images as PNG or JPG — has accumulated at least a million installs, but it was flagged by Google and taken down in March 2026. It has been reported that the extension’s inject.js file communicated with a remote server and harvested users’ visited URLs, and that it also rewrote shopping links to substitute its own affiliate codes, allegedly affecting at least 578 websites.
Timeline and ownership questions
Microsoft (微软) had already removed the extension from its Edge browser at the end of 2024 after detecting problems, but Chrome users continued to have access until this month. It has been reported that the extension changed hands in August 2024, leading analysts to speculate the suspicious behavior began after the transfer. There is no public evidence yet that the tool installed traditional malware on devices, but the undisclosed collection and monetization of browsing data raise clear privacy and ethics concerns.
Why Western readers should care
Browser extensions sit between users and vast amounts of personal data. For readers outside China unfamiliar with the market: alternative Chinese browsers such as Qihoo 360 (奇虎360) also host extensions and operate under different review regimes and local regulatory pressures. In an era of heightened scrutiny over software supply chains and cross‑border data flows, platforms are tightening policies and removals can happen unevenly across ecosystems. Who vets an extension after a change of ownership? That’s the question here.
What users should do now
Check your browser’s extension list and uninstall “Save image as Type” if present. Review extension permissions and recent activity, change passwords if you detect suspicious account activity, and prefer well‑maintained tools with transparent ownership. It has been reported that the extension’s undisclosed monetization and data collection were the primary drivers of the takedown, a reminder that convenience can carry hidden costs.
