Google Chrome users beware — experts warn over 100 Web Store extensions found stealing user data from thousands of accounts



  • Socket finds 108 malicious Chrome extensions stealing tokens and data
  • Extensions harvest Google account info, hijack Telegram sessions, and open backdoors
  • Likely Russian MaaS operation; 20,000+ installs, still live in Web Store

A single threat actor has apparently smuggled more than 100 malicious browser extensions into the official Google Chrome Web Store, looking to steal authentication tokens, and establish backdoors to people’s devices.

Analyzing Google’s browser repository, security researchers Socket found 108 extensions split into five distinct categories: Telegram sidebar clients, slot machines and Keno games, YouTube and TikTok enhancers, text translation tools, and browser utilities.


https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-2000-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img