Seemingly without advance notice, the popular Chrome extension “Save image as Type” was flagged for removal after Google warned users that the extension contained malicious behavior. The add-on, which had built a user base of at least one million people, no longer functions in Chrome and has been removed from the Chrome Web Store.
Users first noticed the problem and reported it on forums such as Reddit, explaining that the extension stopped working in their browsers and that its listing on the Chrome Web Store had been taken down. For many, the extension had been a convenient tool to download images in different file types—JPG, PNG, and other formats—that some sites restrict through their context menu or image delivery methods. That convenience, however, now appears to have come with hidden costs.
Investigations reported by tech publications, including coverage from XDA, identified malicious code embedded in the extension’s files. The problematic code—located in a file named inject.js—made network calls to external servers and collected lists of URLs, then used that data to insert affiliate codes. In effect, when users interacted with certain sites after using the extension, those affiliate codes could divert referral commissions away from the original source to the extension’s operators.
Reports indicate the extension injected its own affiliate links for at least 578 identifiable websites, redirecting some portion of transactional revenue to the extension’s maintainers after users followed or clicked affected links. While that behavior stops short of installing traditional malware on a machine, it represents a clear breach of user trust and of acceptable data practices: it scraped information and altered traffic without making those actions transparent to users. Similar concerns have been raised in the past about other browser tools that collect or redirect data under opaque terms.
Part of the concern stems from a change in ownership. The extension appears to have changed hands in late 2025, with the registered developer contact switching from Image4Tools to an individual identified as “Lauren Bridge.” That ownership change, combined with the extension’s large user base, suggests the extension may have been sold and then modified to include affiliate scraping behavior. Archived records show that the extension had amassed at least 1,000,000 users before being taken down.
Microsoft’s browser ecosystem also encountered this extension: Edge removed it several months after similar malicious behavior was documented in late 2024, though it remained available and active in Chrome until March 2026. The staggered removals illustrate how extensions can persist across different stores and browsers even after security concerns are raised, and why users should remain vigilant about the extensions they install and keep active.
For users seeking safe alternatives, community reports suggest extensions such as “Save Image As PNG” may offer comparable functionality without the same privacy and integrity concerns. That particular extension has fewer downloads—roughly half the installs of the removed tool—but appears to follow Chrome’s policies and does not exhibit the same affiliate-injection behavior. As with any browser add-on, however, users should review permissions, check developer reputations, and monitor updates or community reports about unexpected activity.
If you previously installed the removed extension, it is prudent to uninstall it and clear any related browser data or cached files. Consider reviewing your browser’s extension list for other tools you no longer use or that request broad permissions. Regularly auditing installed extensions, enabling extensions only from trusted sources, and keeping software up to date are practical steps to reduce the risk of data scraping or unauthorized redirects. Developers and browser store operators continue to refine detection methods, but user caution remains an important layer of protection.
In summary, the removal of “Save image as Type” highlights the risks tied to browser extensions that change ownership or behavior, particularly when those changes involve nontransparent data collection or revenue diversion. Users who need image-format conversion tools should opt for well-reviewed extensions, verify permissions, and stay alert to community reports about any suspicious activity.