Link Centre - Search Engine and Internet Directory

Helping to share the web since 1996

108 Malicious Chrome Extensions Found Stealing Data from Gmail, YouTube, TikTok, and Telegram Users

A large-scale malware operation has been uncovered involving 108 rogue browser extensions on Google Chrome, targeting users of platforms like Gmail, YouTube, TikTok, and Telegram. All of these extensions are linked back to a single command-and-control infrastructure, suggesting a highly coordinated effort.

person using black laptop computer

🚨 Key findings from the investigation

  • 54 of the extensions were designed to hijack Google account data through OAuth2 authentication abuse.
  • 45 included hidden backdoors that triggered attacker-controlled websites as soon as the browser launched.
  • Some extensions went further by injecting ads, removing important security protections, or adding scripts to every webpage users visited.
  • In one particularly alarming case, Telegram session data was being siphoned off every 15 seconds.
  • At the time of discovery, all 108 extensions were still available, with around 20,000 total installations.

⚠️ Why this is a big deal
This campaign shows how easily browser extensions - tools many people trust - can be turned into powerful attack vectors. Even extensions that start off legitimate can later be sold or compromised and repurposed for malicious use. While Chrome users are the primary target due to the browser’s massive reach, other browsers like Mozilla Firefox aren’t immune.

🛡️ Google’s response
Google says it reviews extensions before they’re published, keeps monitoring them over time, and alerts users via the extensions settings page if any risks are detected.

Still, the fact that these harmful extensions remained active highlights potential blind spots in the current detection and enforcement systems.

Newer Articles

Older Articles

← Back to News Headlines