Hello everyone,
I am looking for advice or visibility from any CWS team members regarding an unexpected and sudden account suspension. We have been developers on the Chrome Web Store for over 15 years (Publisher: www.hotcleaner.com), maintaining popular extensions like Magic Actions for YouTube (ID: abjcfabbhafbcdfjoecdgepllmpfceif) and Click&Clean.
Here is a step-by-step breakdown of what happened today:
No Recent Updates: We have not uploaded any new versions or pushed any updates to our extensions in over a year. Our extensions do not use any third-party libraries.
Prior Manual Approval: The most recent version of Magic Actions (ID: abjcfabbhafbcdfjoecdgepllmpfceif) was manually reviewed and approved by the CWS team a year ago (October 2025). The CWS team found no violations during that manual check, and our codebase has remained exactly the same since then.
Sudden Takedown: Today, out of nowhere, we received automated emails stating that our extensions were removed from the store due to a Program Policies violation, which was detected during an "internal review."
Immediate Suspension: Exactly six minutes after the item takedown emails, our entire developer account was suspended. The dashboard cited "malicious behavior."
Account Security Verified: We have thoroughly checked and are absolutely certain there was no unauthorized access to our account, and no rogue updates were secretly pushed.
Appeal Submitted: We have already submitted an official account-level appeal via the dashboard requesting a manual review.
Because the code has been dormant for a year and was previously cleared by a manual review, we strongly suspect this is a false positive triggered by an automated system sweep.
Has anyone else experienced a sudden "malicious behavior" flag on older, untouched extensions? Any advice on how to handle this or escalate it while we wait for the appeal response would be greatly appreciated.
Thank you,
Urgent Update / Additional Information:
I want to add two critical pieces of information regarding this sudden takedown:
1. No Appeal Confirmation Email: When I submitted the appeal via the Developer Dashboard, I did not receive any automated email receipt. The dashboard simply flashed a brief "submitted" message for about one second and then disappeared. There is no visible ticket number or status indicator. Could a Community Manager please verify if our appeal actually made it into the queue, or if there is a bug with the dashboard submission form?
2. Severe User Impact (Malware Warnings):
Because the automated system flagged our 15-year-old account for "malicious behavior," the Chrome browser is now actively showing a massive red warning to all our active users. It states that Magic Actions "contains malware and is unsafe" and urges them to REMOVE it immediately.
This is causing widespread panic among our massive user base and is heavily damaging our reputation, despite the fact that the codebase has been untouched for over a year and was previously approved manually by the CWS team.
If there is any way to escalate this false positive or get human eyes on our appeal (Publisher ID: d5836f4f-f0f4-44b0-9b41-38f3289a7d79), we would be incredibly grateful. We are fully prepared to address any technical issues, but we are completely locked out and in the dark while Chrome aggressively tells our users that our clean code is malware.
Thank you for any help or visibility!
A quick tip for our users: Since you are now battling the browser's aggressive "REMOVE" prompts, I highly recommend making that Facebook/social media post immediately. When users see the browser telling them the extension has malware, they are much less likely to wait for an email reply from support and will just uninstall it out of fear. Getting ahead of the narrative publicly is essential right now.
Following a detailed technical investigation, we have identified a recurring vector of abuse targeting our developer account. A false-positive Safe Browsing flag was applied to a clean, self-hosted .crx file—which is binary-identical to our store-approved build—triggering a cascading, account-wide disablement across all of our extensions.
We are requesting engineering assistance to resolve a critical false-positive cascade. An automated Safe Browsing domain flag placed on a self-hosted .crx file—which is identical in code and hash to our store-approved build—has triggered an account-wide disablement across all our long-standing extensions.
Below is the technical timeline, evidence of previous manual clearance on the exact same claims, and binary integrity details.
1. Historical Context & Previous Manual Clearance (October 2025)October 27, 2025: Extension Magic Actions for YouTube™ (ID: abjcfabbhafbcdfjoecdgepllmpfceif) was flagged under automated review citing code readability and api64.com network calls.
October 30, 2025: Following a formal technical appeal (Case ID: 5-0959000040156), CWS Developer Support conducted a manual code review of version 7.9.5.6.
Outcome: CWS confirmed full policy compliance, issued an official apology for the false positive, and fully restored the item to the store.
Incident: Google Safe Browsing flagged the self-hosted direct download link [https://www.chromeactions.com/download/MagicActions_Latest.crx](https://www.chromeactions.com/download/MagicActions_Latest.crx) under Search Console as "Links to harmful downloads / Unwanted Software."
Code Parity: The .crx file hosted at this endpoint is binary-identical to the code package submitted to and verified by CWS.
Recycled Abuse Claims: The flag targets the same legitimate operational HTTPS endpoints (including api64.com) that CWS engineers explicitly audited and cleared in October 2025 under Case 5-0959000040156.
Cascading Impact: Because Safe Browsing flagged the primary domain asset, CWS automated enforcement triggered a cascading account-level policy lock, disabling Magic Actions for YouTube™, Click&Clean, Cookie Editor, and Privacy Test, and prompting users with a "contains malware / policy violation" Safety Check banner.
Binary Hash Integrity:
Hosted File URL: [https://www.chromeactions.com/download/MagicActions_Latest.crx](https://www.chromeactions.com/download/MagicActions_Latest.crx)
SHA-256 Hash: df9a8a4ea4f83d656fd94898011ebb3e75f8be400a439fcbb75c013a02034f22
Note: The file contains zero dynamic script execution, zero obfuscated payloads, and identical logic to the approved store submission.
Network Endpoint Audit:
Calls to api64.com are limited strictly to essential operational HTTPS requests. This logic was fully vetted during Case 5-0959000040156.
Multi-Vendor Security Verification:
VirusTotal scan confirms 89/90 clean vendor responses with zero malicious indicators.
Search Console Security Review: Submitted for chromeactions.com referencing binary parity and Case 5-0959000040156.
Safe Browsing False Positive Form: Submitted detailing complete network audit logs.
Requested Assistance: Since our codebase has been manually reviewed and cleared of these exact claims by CWS in Case 5-0959000040156, we respectfully request a developer advocate or team member to escalate this ticket to the Safe Browsing / CWS review team to manually inspect MagicActions_Latest.crx, clear the domain flag, and restore our developer account.
Thank you for your time and assistance.
Blocking developer accounts and marking products as malware without any clear reasons is a huge ongoing problem that the review team continues to ignore.
To unmask who is submitting bad-faith reports and seek compensation for lost revenue and user base damage, you must use court-backed subpoena processes and statutory regulatory channels in both the EU and the US. Google will not voluntarily hand over a reporter's identity, email, or IP address without a legal mandate.
1. European Union Legal & Regulatory MechanismsBecause you operate in the EU and serve European users, Google Ireland Limited is subject to strict European digital regulations that provide specific leverage:
Digital Services Act (DSA) — Articles 20, 21, and 23:
Certified Out-of-Court Dispute Settlement (Article 21): You have the statutory right to take Google to an officially certified EU out-of-court dispute settlement body to resolve arbitrary suspensions and false-positive removals.
Protection Against Misuse (Article 23): The DSA explicitly obligates platform providers to suspend actors who frequently submit manifestly unfounded notices or abuse reporting channels. You can formally demand under the DSA that Google investigate and block the entity filing bad-faith notices against your account.
Digital Markets Act (DMA) — Gatekeeper Anti-Circumvention Rules:
Google is a designated "Gatekeeper" under the DMA. Artificially locking out independent developers through unmonitored or privileged enforcement mechanisms breaches fair-access requirements. You can lodge a formal regulatory complaint directly with the European Commission’s Directorate-General for Competition (DG COMP) detailing how arbitrary platform actions destroy independent businesses.
EU Civil Action for Unfair Competition & Information Disclosure:
File a lawsuit in your local EU jurisdiction (or via Google Ireland Limited's legal seat in Dublin) for Unfair Competition / Commercial Slander.
Request a Court Order for Pre-Action Disclosure compelling Google Ireland Ltd. to release all abuse report tickets, submitter account handles, IP logs, and metadata linked to the false flags on your extensions.
Because Google LLC is headquartered in California, US federal and state courts have direct jurisdiction over Google’s central infrastructure, database logs, and internal product support teams:
"John Doe" Lawsuit & Rule 45 Subpoena (The Primary Way to Reveal Identities):
You or a US-licensed legal representative file a "John Doe" Civil Lawsuit in California State Court (Santa Clara County) or US District Court (Northern District of California) alleging:
Tortious Interference with Contractual / Economic Relations (deliberately sabotaging your business).
Defamation / Commercial Disparagement (falsely publishing that your clean extensions contain "malware").
Once the lawsuit is filed against "John Doe (Unknown Reporter)," your attorney issues a Rule 45 Discovery Subpoena directly to Google LLC.
The subpoena legally forces Google to produce:
The exact email addresses, user accounts, and IP logs of the individual(s) who filed the abuse reports.
All internal notes, Product Expert forum escalation logs, and tickets associated with your extension ID (abjcfabbhafbcdfjoecdgepllmpfceif).
Federal Trade Commission (FTC) & State Attorney General Complaints:
Submit a formal complaint to the FTC Bureau of Competition and the California Attorney General’s Antitrust & Digital Markets Unit.
Highlight how platform dominance is weaponized against long-standing developers without due process, resulting in severe economic injury.
The fact that the code was unchanged and approved in 2025 does not establish that it is currently policy-compliant.
An independent review of Magic Actions for YouTube 7.9.5.6 found several concrete issues:
It requests access to all HTTP and HTTPS websites although its implemented functionality appears to require a much narrower set of origins.
It automatically sends browser/Chromium versions, OS, language, timezone, installation timing and reminder state to api64.com.
This behavior conflicts with the public “we do not collect users data” statement and the Chrome Web Store disclosure that the developer does not collect or use data.
Disabling “AI reminders” does not stop that request, and a stored or server-provided reminder may still open an external window after a tab is closed.
A fresh installation automatically opens a promotional page for Click&Clean without a separate user action.
The published privacy policy does not comprehensively describe these data flows, their purposes and recipients.
A clean VirusTotal result and an unchanged binary do not address Chrome Web Store requirements concerning minimum permissions, accurate disclosures, informed consent, single purpose and unwanted behavior.
The review did not find remote code execution, cryptocurrency mining or affiliate-link injection. Therefore, it does not independently prove Google’s exact “malware” classification. It does, however, show that the claim that the extension is fully clean and has no policy issues is not supported by its actual behavior.
--
You received this message because you are subscribed to the Google Groups "Chromium Extensions" group.
To unsubscribe from this group and stop receiving emails from it, send an email to chromium-extens...@chromium.org.
To view this discussion visit https://groups.google.com/a/chromium.org/d/msgid/chromium-extensions/833481b1-2572-4daf-ab47-c3f6c1c399b8n%40chromium.org.