Researchers reported that the StealTok campaign used at least 12 malicious browser extensions on the Chrome and Microsoft Edge stores that posed as TikTok video downloaders while covertly harvesting user data. The extensions shared a common Manifest V3 codebase and relied on attacker-controlled remote configuration, allowing operators to alter behavior after installation. More than 130,000 users were affected over the life of the campaign, and roughly 12,500 installations remained active at the time of reporting; some of the add-ons had even been labeled "Featured" in official marketplaces, helping them appear legitimate.
The operation reportedly ran for more than a year and often kept extensions benign for six to 12 months before enabling information-stealing functions, a tactic that helped evade store review and build trust. Collected data included browsing and usage telemetry, TikTok content interaction, language and timezone settings, user-agent details, and battery status, giving attackers a strong fingerprint of victims’ environments. Researchers said the campaign appeared to be run by a single actor or tightly coordinated group using cloning, rebranding, and rapid redeployment to survive takedowns, and warned the same infrastructure could be expanded for broader data theft, session abuse, or proxy-style botnet activity.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
LayerX published research identifying the coordinated StealTok campaign and said more than 130,000 users had been compromised across Chrome and Edge. At the time of analysis, about 12,500 active installations remained, and some malicious extensions were still available in official stores, including several marked as featured.
After remaining benign for roughly 6 to 12 months to evade marketplace review, many of the TikTok downloader extensions were updated with information-stealing and tracking capabilities. The extensions began collecting telemetry and fingerprinting data such as usage patterns, language, timezone, user agent, and battery status.
LayerX reported that the StealTok campaign had been active for more than a year, using at least 12 Chrome and Microsoft Edge extensions disguised as TikTok video downloaders. The operation relied on a shared codebase, cloning, rebranding, and attacker-controlled remote configuration to persist across store removals.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourceinfosec.pub
Open sourcescworld.com
Open sourcelayerxsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.