logo

Malicious TikTok Downloader Extensions Quietly Compromised 130K Users

ID: ebe722fb-5f06-5763-9cbb-2140c862c1f7

STIX ID: report--ebe722fb-5f06-5763-9cbb-2140c862c1f7

Feed Name: TechRepublic Security

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

LayerX researchers uncovered a widespread campaign of at least 12 interrelated browser extensions marketed as TikTok video downloaders that built user trust by providing expected functionality but secretly collected high-entropy fingerprinting data, used delayed activation, and leveraged attacker-controlled remote configuration servers to change behavior post-installation; the campaign impacted more than 130,000 users across Chrome and Edge and highlights systemic weaknesses in extension permission models and marketplace review processes, with recommended defenses including allowlists, least-privilege, monitoring, browser isolation, and DLP integration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.