logo

Chrome Extensions Infected 500K Users to Hijack VKontakte Accounts

ID: 1c2abfdc-8b83-57bb-9d71-4c8f3064a07c

STIX ID: report--1c2abfdc-8b83-57bb-9d71-4c8f3064a07c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-13

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A widespread malware campaign delivered via five malicious Chrome extensions (notably “VK Styles”) infected roughly 500,000 VKontakte users by using a two-stage delivery model: extensions fetched encoded payload URLs from attacker-controlled VK profiles and downloaded additional code from a GitHub repository to hijack accounts, manipulate CSRF tokens, auto-subscribe victims to attacker groups, and maintain persistence from June 2025 through January 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.