Minacce · 168 giorni fa
Chrome Extensions Turn OAuth Tokens Into Account Access Browser extensions can become account takeover infrastructure. Here, the standard response of checking passwords misses the real problem: stolen Google OAuth2 tokens and Telegram sessions let attackers act as the user without needing the password or MFA.
Researchers found 108 malicious Chrome Web Store extensions, about 20,000 installs total, published under five identities: Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt. The cluster shared one C2 backend and included extensions that stole Google account identity and OAuth2 bearer tokens, exfiltrated Telegram Web sessions, injected ads and scripts, and ran hidden backdoors on browser start.
The immediate risk is not just data theft. Any revoked extension that already captured tokens or live sessions can keep enabling access until those tokens are revoked and sessions are signed out, so the compromise can outlast the extension itself.
Cronologia Fonti 6 fonti che coprono questa storia
SecurityWeek 15 apr
100 Chrome Extensions Steal User Data, Create Backdoor
Published through five accounts, the extensions appear part of a coordinated campaign based on shared C&C infrastructure.
Graham Cluley 15 apr
Malicious Chrome Extensions Steal Google & Telegram Data
These Chrome extensions looked harmless - but secretly stole data and hijacked accounts.
BleepingComputer 14 apr
Over 100 Chrome Web Store extensions steal user accounts, data
More than 100 malicious extensions in the official Chrome Web Store are attempting to steal Google OAuth2 Bearer tokens, deploy backdoors, and carry out ad fraud.
The Hacker News 14 apr
108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users
108 Chrome extensions routed stolen Google and Telegram data to shared C2 infrastructure, impacting 20,000 users.
Infosecurity Magazine 14 apr
Malicious Chrome Extensions Campaign Exposes User Data
108 malicious Chrome extensions steal sessions, Google data, inject ads via single C2 infrastructure
Socket.dev 13 apr
108 Chrome Extensions Linked to Data Exfiltration and Sessio...
Campaign of 108 extensions harvests identities, steals sessions, and adds backdoors to browsers, all tied to the same C2 infrastructure.
Part of the PlainSec briefing for 2026-04-16
Editions Storie correlate
Minacce · 168 giorni fa
Chrome Extensions Turn OAuth Tokens Into Account Access Browser extensions can become account takeover infrastructure. Here, the standard response of checking passwords misses the real problem: stolen Google OAuth2 tokens and Telegram sessions let attackers act as the user without needing the password or MFA.
Researchers found 108 malicious Chrome Web Store extensions, about 20,000 installs total, published under five identities: Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt. The cluster shared one C2 backend and included extensions that stole Google account identity and OAuth2 bearer tokens, exfiltrated Telegram Web sessions, injected ads and scripts, and ran hidden backdoors on browser start.
The immediate risk is not just data theft. Any revoked extension that already captured tokens or live sessions can keep enabling access until those tokens are revoked and sessions are signed out, so the compromise can outlast the extension itself.
Cronologia Fonti 6 fonti che coprono questa storia
SecurityWeek 15 apr
100 Chrome Extensions Steal User Data, Create Backdoor
Published through five accounts, the extensions appear part of a coordinated campaign based on shared C&C infrastructure.
Graham Cluley 15 apr
Malicious Chrome Extensions Steal Google & Telegram Data
These Chrome extensions looked harmless - but secretly stole data and hijacked accounts.
BleepingComputer 14 apr
Over 100 Chrome Web Store extensions steal user accounts, data
More than 100 malicious extensions in the official Chrome Web Store are attempting to steal Google OAuth2 Bearer tokens, deploy backdoors, and carry out ad fraud.
The Hacker News 14 apr
108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users
108 Chrome extensions routed stolen Google and Telegram data to shared C2 infrastructure, impacting 20,000 users.
Infosecurity Magazine 14 apr
Malicious Chrome Extensions Campaign Exposes User Data
108 malicious Chrome extensions steal sessions, Google data, inject ads via single C2 infrastructure
Socket.dev 13 apr
108 Chrome Extensions Linked to Data Exfiltration and Sessio...
Campaign of 108 extensions harvests identities, steals sessions, and adds backdoors to browsers, all tied to the same C2 infrastructure.
Part of the PlainSec briefing for 2026-04-16
Editions Storie correlate