Remote extension control is now a browser trust problem, not a branding problem: The campaign succeeds because users judge extensions by the front-end label while the real behaviour is controlled by remote infrastructure. That breaks the assumption that install-time review is a durable proxy for runtime safety. For IAM and browser security teams, the practical conclusion is that trust has to be evaluated as a living control boundary, not a one-time approval event.
A question worth separating out:
Q: What should teams do when one extension in a spray campaign is removed?
A: Assume the operation may continue under new IDs or names if the backend infrastructure and codebase are shared. Teams should correlate lineage, domains, and republished copies so the same campaign is not mistaken for separate low-risk extensions.
👉 Read our full editorial: Fake AI assistant extensions turn Chrome into a data broker