Threats · 153 days ago
Chrome Extensions Turn OAuth Tokens Into Account Access Browser extensions can become account takeover infrastructure. Here, the standard response of checking passwords misses the real problem: stolen Google OAuth2 tokens and Telegram sessions let attackers act as the user without needing the password or MFA.
Researchers found 108 malicious Chrome Web Store extensions, about 20,000 installs total, published under five identities: Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt. The cluster shared one C2 backend and included extensions that stole Google account identity and OAuth2 bearer tokens, exfiltrated Telegram Web sessions, injected ads and scripts, and ran hidden backdoors on browser start.
The immediate risk is not just data theft. Any revoked extension that already captured tokens or live sessions can keep enabling access until those tokens are revoked and sessions are signed out, so the compromise can outlast the extension itself.
Timeline Sources 6 sources covering this story
SecurityWeek Apr 15
100 Chrome Extensions Steal User Data, Create Backdoor
Published through five accounts, the extensions appear part of a coordinated campaign based on shared C&C infrastructure.
Graham Cluley Apr 15
Malicious Chrome Extensions Steal Google & Telegram Data
These Chrome extensions looked harmless - but secretly stole data and hijacked accounts.
BleepingComputer Apr 14
Over 100 Chrome Web Store extensions steal user accounts, data
More than 100 malicious extensions in the official Chrome Web Store are attempting to steal Google OAuth2 Bearer tokens, deploy backdoors, and carry out ad fraud.
The Hacker News Apr 14
108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users
108 Chrome extensions routed stolen Google and Telegram data to shared C2 infrastructure, impacting 20,000 users.
Infosecurity Magazine Apr 14
Malicious Chrome Extensions Campaign Exposes User Data
108 malicious Chrome extensions steal sessions, Google data, inject ads via single C2 infrastructure
Socket.dev Apr 13
108 Chrome Extensions Linked to Data Exfiltration and Sessio...
Campaign of 108 extensions harvests identities, steals sessions, and adds backdoors to browsers, all tied to the same C2 infrastructure.
Part of the PlainSec briefing for 2026-04-16
Editions Related stories
Threats · 153 days ago
Chrome Extensions Turn OAuth Tokens Into Account Access Browser extensions can become account takeover infrastructure. Here, the standard response of checking passwords misses the real problem: stolen Google OAuth2 tokens and Telegram sessions let attackers act as the user without needing the password or MFA.
Researchers found 108 malicious Chrome Web Store extensions, about 20,000 installs total, published under five identities: Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt. The cluster shared one C2 backend and included extensions that stole Google account identity and OAuth2 bearer tokens, exfiltrated Telegram Web sessions, injected ads and scripts, and ran hidden backdoors on browser start.
The immediate risk is not just data theft. Any revoked extension that already captured tokens or live sessions can keep enabling access until those tokens are revoked and sessions are signed out, so the compromise can outlast the extension itself.
Timeline Sources 6 sources covering this story
SecurityWeek Apr 15
100 Chrome Extensions Steal User Data, Create Backdoor
Published through five accounts, the extensions appear part of a coordinated campaign based on shared C&C infrastructure.
Graham Cluley Apr 15
Malicious Chrome Extensions Steal Google & Telegram Data
These Chrome extensions looked harmless - but secretly stole data and hijacked accounts.
BleepingComputer Apr 14
Over 100 Chrome Web Store extensions steal user accounts, data
More than 100 malicious extensions in the official Chrome Web Store are attempting to steal Google OAuth2 Bearer tokens, deploy backdoors, and carry out ad fraud.
The Hacker News Apr 14
108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users
108 Chrome extensions routed stolen Google and Telegram data to shared C2 infrastructure, impacting 20,000 users.
Infosecurity Magazine Apr 14
Malicious Chrome Extensions Campaign Exposes User Data
108 malicious Chrome extensions steal sessions, Google data, inject ads via single C2 infrastructure
Socket.dev Apr 13
108 Chrome Extensions Linked to Data Exfiltration and Sessio...
Campaign of 108 extensions harvests identities, steals sessions, and adds backdoors to browsers, all tied to the same C2 infrastructure.
Part of the PlainSec briefing for 2026-04-16
Editions Related stories