Researchers uncovered a coordinated campaign involving 108 malicious Chrome extensions on the Chrome Web Store that collectively reached about 20,000 installs and were published under five separate publisher identities. The extensions posed as legitimate tools and games but were tied to a shared command-and-control infrastructure, including cloudapi[.]stream and backend systems hosted at 144.126.135[.]238. Investigators linked the operation through reused code, shared privacy-policy artifacts, common Google Cloud project numbers across 54 OAuth-enabled extensions, and Russian-language comments, indicating a single operator or centrally managed service.
The extensions were found stealing Google account identity data, browsing information, and Telegram Web sessions, while some also injected ads, inserted arbitrary JavaScript into visited pages, stripped security headers from sites such as YouTube, TikTok, and Telegram, or used a startup backdoor to open arbitrary URLs. The most severe sample, Telegram Multi-account, reportedly exfiltrated Telegram Web session data every 15 seconds and could enable full account takeover by replacing a victim's local session with attacker-supplied data. Researchers said the infrastructure appeared consistent with a malware-as-a-service model and warned that many of the extensions were still live when reported; affected users were urged to remove the extensions and revoke active Telegram Web sessions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
At the time of publication, the malicious extensions were still available in the Chrome Web Store. Socket said it had submitted takedown requests to the Chrome Web Store security team and Google Safe Browsing.
Socket disclosed that the most severe sample, Telegram Multi-account, repeatedly exfiltrates Telegram Web session data every 15 seconds and can enable full account takeover by replacing a victim's local session with attacker-supplied data. Researchers also reported that dozens of extensions harvested Google identity data via OAuth2 and some included startup backdoors or content-injection features.
Researchers connected the extensions to a single operator using shared backend infrastructure, reused code and privacy-policy artifacts, common Google Cloud project numbers across OAuth-enabled extensions, and Russian-language comments. The infrastructure appeared to support a malware-as-a-service model with centralized access to stolen identities and sessions.
Socket's Threat Research Team identified a coordinated campaign involving 108 malicious Chrome extensions published under five Chrome Web Store publisher identities and linked through shared command-and-control infrastructure. The extensions collectively had about 20,000 installs and blended benign-looking features with data theft, session hijacking, ad injection, and arbitrary URL opening behavior.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
8 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcescworld.com
Open sourceghacks.net
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcesocket.dev
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.