Over 100 Malicious Chrome Extensions Steal Google Tokens, Hijack Telegram Sessions, a
#1
Information 
Quote:Security researchers at Socket have identified over 100 malicious extensions in the Chrome Web Store that are part of a coordinated campaign. These extensions steal Google OAuth2 Bearer tokens, deploy backdoors, and carry out ad fraud. At the time Socket published its report, all affected extensions were still available in the store. Google has not yet responded to requests for comment.

The extensions were published under five different publisher profiles across various categories, including Telegram sidebar clients, slot machine and Keno games, YouTube and TikTok enhancers, a text translation tool, and browser utilities. Socket found evidence in the code indicating the campaign is tied to a Russian malware-as-a-service operation.

What the Malicious Chrome Extensions Do

The campaign operates with a central backend hosted on a Contabo VPS, supported by multiple subdomains that handle session hijacking, identity collection, command execution, and monetization. The largest cluster involves 78 extensions that inject attacker-controlled HTML into the browser interface using the innerHTML property.

Continue Reading...
Reply


Messages In This Thread
Over 100 Malicious Chrome Extensions Steal Google Tokens, Hijack Telegram Sessions, a - by harlan4096 - Today, 07:02

Forum Jump:


Users browsing this thread: 3 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Google Chrome 147.0.7727.101/102
Google Chrome 147.0...harlan4096 — 07:08
PatchMyPC 5.4.4.0 (15-April-2026)
Version 5.4.4.0 i...harlan4096 — 07:05
Microsoft Fixes Windows Server 2019 and ...
Microsoft has fixe...harlan4096 — 07:02
Over 100 Malicious Chrome Extensions Ste...
Security researche...harlan4096 — 07:02
[Test & Review Request] Looking for fee...
Can you at least i...LFTyyy — 14:28

[-]
Birthdays
Today's Birthdays
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo
avatar (38)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>