A few months ago I discovered a similar situation with a very popular extension (300,000+) users. It removed facebook ads, and injected it's own. After a quick search, I found 4-5 others that were doing the same. Took Google over 3 weeks to remove them.
http://www.reddit.com/r/chrome/comments/gpwqc/caution_auto_h...