logo

Over 100 Chrome extensions in Web Store target users accounts and data

ID: 304631dd-0a16-55ea-bcfe-8dffc7388baa

STIX ID: report--304631dd-0a16-55ea-bcfe-8dffc7388baa

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-04-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers uncovered a coordinated campaign of more than 100 malicious Chrome extensions in the official Web Store that steal Google OAuth2 bearer tokens and account data, act as persistent backdoors fetching commands from a central C2 (hosted on a Contabo VPS), exfiltrate Telegram Web sessions enabling account takeover, and perform ad injection and proxying; evidence suggests a Russian MaaS operation and many extensions were still available at the time of reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.