>if you have an approved extension with https://*/* permissions and active users, malware authors will offer to buy your extension for a very high price.
This is interesting, and I didn't realize this was a thing.
Are there any lists of extensions with these permissions, or ways that as an average consumer could easily audit my list of extensions for this?