Researchers Uncover 108 Chrome Extensions Used for Stealing Logins and Tracking Users
Cybersecurity researchers discovered a large attack involving 108 Google Chrome extensions that were secretly connected to the same control system. These extensions were designed to steal user data and abuse the browser by injecting ads, running hidden scripts, and tracking activity on every website visited. Although they looked like normal tools, games, or browser helpers, they were all controlled by one operator and shared the same backend server.
The extensions came from five different developer names and had around 20,000 installs. They sent stolen data like login details, browsing activity, and account identities to remote servers. Some stole Google and Telegram sessions, others removed website security protections to inject ads or gambling content, and some even ran hidden code or opened websites without permission. Researchers believe this was a coordinated operation, though the attackers are still unknown, with some code containing Russian-language comments.
Safety tips:
- Remove any suspicious or unknown Chrome extensions immediately
- Check your installed extensions and uninstall anything you don’t recognize
- Change passwords for important accounts, especially Google and Telegram
- Avoid installing browser extensions from untrusted or unknown developers
Source: https://thehackernews.com/2026/04/108-malicious-chrome-extensions-steal.html