Chrome Extensions Turn OAuth Tokens Into Account Access
Browser extensions can become account takeover infrastructure. Here, the standard response of checking passwords misses the real problem: stolen Google OAuth2 tokens and Telegram sessions let attackers act as the user without needing the password or MFA.
Researchers found 108 malicious Chrome Web Store extensions, about 20,000 installs total, published under five identities: Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt. The cluster shared one C2 backend and included extensions that stole Google account identity and OAuth2 bearer tokens, exfiltrated Telegram Web sessions, injected ads and scripts, and ran hidden backdoors on browser start.
The immediate risk is not just data theft. Any revoked extension that already captured tokens or live sessions can keep enabling access until those tokens are revoked and sessions are signed out, so the compromise can outlast the extension itself.