108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users
A coordinated campaign involving 108 malicious Chrome extensions has been discovered, stealing data from approximately 20,000 users. The extensions, disguised as legitimate add-ons for popular apps like Telegram and YouTube, were communicating with a central command-and-control server and collecting user credentials and browsing data. This highlights the ongoing risk posed by malicious browser extensions and the importance of careful extension management.
The discovery, made by researchers at Socket, revealed that the extensions were quietly siphoning credentials, hijacking Telegram sessions, and injecting unwanted ads and scripts. All 108 extensions were linked to a single C2 server, strongly suggesting a coordinated attack by a single group. The extensions were published under multiple publisher identities to evade detection, further disguising their malicious intent. The campaign leveraged deceptive branding, mimicking popular apps and tools to lure users into installing the compromised extensions. This incident echoes previous breaches involving compromised browser extensions, including those targeting cryptocurrency wallets and stealing Facebook session cookies.