Attackers compromised several legitimate Chrome extensions by phishing developers’ Google Account credentials and then using those accounts to push malicious updates through the Chrome Web Store. Proofpoint reported that affected extensions included Web Developer (0.4.9), Chrometana, Infinity New Tab, CopyFish, Web Paint, and Social Fixer, with TouchVPN and Betternet VPN also likely impacted. Because the updates came from trusted publisher accounts, the malicious code was delivered to existing users as if it were a normal extension release.
The injected code delayed execution after installation, retrieved additional payloads from DGA-generated domains, and then manipulated browser activity to hijack traffic, replace advertisements, display fake repair alerts, and redirect victims to affiliate programs. Researchers also identified credential-theft components in the campaign, including scripts intended to steal and exfiltrate Cloudflare credentials, showing that the operation combined ad fraud, traffic interception, and account compromise in a broad extension hijacking spree.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The report ties the broader campaign to earlier fake Chrome extension and cookie-consent abuse that had been documented in July 2016, indicating related infrastructure and tactics predated the 2017 hijackings.
Proofpoint disclosed that multiple legitimate Chrome extensions, including Web Developer, Chrometana, Infinity New Tab, CopyFish, Web Paint, and Social Fixer, were compromised after attackers phished developers' Google account credentials and pushed malicious updates.
Chris Pederick reported that his Web Developer for Chrome extension had been compromised, confirming that attackers had inserted malicious code into the legitimate package.
On August 3, the compromised Web Developer extension requested ga.js from a second DGA-generated domain, wd8a2b7d68f1c7c7f34381dc1a198465b4[.]win, continuing the malicious update activity.
On August 2, the malicious Web Developer 0.4.9 extension fetched ga.js over HTTPS from the DGA-generated domain wd7bdb20e4d622f6569f3e8503138c859d[.]win as part of its staged payload delivery.
Proofpoint states that TouchVPN and Betternet VPN were also likely compromised using the same phishing-and-malicious-update method at the end of June.
During the Infinity New Tab compromise, victims were shown fake repair alerts and malicious code that Proofpoint later described as almost identical to the code used in subsequent extension hijackings, though with a slightly different DGA.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 60 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.