Home » Latest Updates » 108 Chrome Extensions Found Injecting Ads and Collecting User Data

108 Chrome Extensions Found Injecting Ads and Collecting User Data

by Tech Insights Team
0 comments 4-minutes read
Chrome extensions ad injection

Cybersecurity researchers have discovered a large-scale security problem involving Google Chrome extensions. A total of 108 malicious extensions were found secretly stealing user data. These extensions were also hijacking Telegram sessions and injecting unwanted ads and scripts into browsers.

108 Chrome Extensions Found Injecting Ads and Collecting User Data

All of them were linked to a single control system, which suggests a coordinated hacking campaign rather than separate attacks.

How 108 Malicious Chrome Extensions Worked

The research was done by security firm Socket. It found that all 108 extensions were linked to a single command-and-control (C2) server. Attackers used this server to remotely control the extensions and quietly collect stolen user data.

Before being removed or flagged, these extensions had around 20,000 installs from the Chrome Web Store. This shows that many users were affected without knowing the risk.

To avoid detection, the extensions were published under five different developer names, including Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt. Even though they looked separate, they were all part of the same operation.

The extensions were made to look helpful and safe so people would install them. They appeared as different types of tools, such as Telegram sidebar tools, YouTube and TikTok helper apps, online games, translation tools, and simple utilities like refresh or speed test extensions.

But in reality, they were doing something very different. Behind these normal-looking features, the extensions were secretly running harmful actions without the user knowing or giving permission.

Researchers found that these extensions were quietly sending user data to remote servers controlled by hackers. Most users were completely unaware that this was happening in the background. The information being stolen was sensitive and could easily be misused to access or compromise online accounts.

  • Google account details like name, email, and profile picture
  • Browsing activity and user identity information
  • Telegram Web session data
  • Login credentials and authentication details

In some cases, attackers could even take over active user sessions.

Chrome extensions ad injection
108 Chrome Extensions Found Injecting Ads and Collecting User Data

The investigation found several dangerous behaviours:

  • 54 extensions stole Google account information
  • 45 extensions had hidden backdoors that could open websites automatically
  • Some extensions stole Telegram Web session data every 15 seconds
  • Some replaced active Telegram sessions with attacker-controlled ones
  • Some removed security protections on YouTube and TikTok and injected gambling ads

These actions were happening silently in the background without users noticing.

Most Downloaded Malicious Chrome Extensions

Here are some of the most downloaded extensions from the list of 108:

  • Web Client for TikTok – 2,000+ installs
  • Web Client for Telegram – Teleside – 1,000+ installs
  • YouSide – YouTube Sidebar – 1,000+ installs
  • Web Client for YouTube – SideYou – 1,000+ installs
  • Formula Rush Racing Game – 1,000+ installs
  • Page Auto Refresh – 1,000+ installs
  • Page Locker – 1,000+ installs
  • Text Translation – 1,000+ installs
  • Telegram Multi-account – 1,000+ installs
  • Speed Test for Chrome – WiFi SpeedTest – 1,000+ installs
  • Clear Cache Plus – 1,000+ installs
  • Piggy Prizes – Slot Machine – 500+ installs
  • Master Chess – 500+ installs
  • Black Beard Slot Machine – 1,000+ installs

How to Stay Safe From Harmful Chrome Extensions

The exact identity of the attackers is still unknown. However, researchers found Russian-language comments inside the code of some extensions. Experts believe this is a well-organised cyber operation due to its scale, structure, and coordination across many extensions.

This is not the first time Chrome extensions have been misused. In recent years, similar cases have been reported:

  • Some extensions were compromised to steal crypto wallet data
  • Fake ChatGPT extensions stole Facebook session cookies
  • Multiple extensions were promoted through ads with fake reviews
  • A major supply chain attack affected millions of users by pushing malicious updates

Security experts strongly advise users to check their Chrome extensions immediately. Any unknown or unused extension should be removed.

Users who installed Telegram-related extensions should log out of all Telegram Web sessions to protect their accounts. It is also important to regularly review installed extensions and their permissions. If an extension requests unnecessary access, it should not be trusted.

This case highlights how browser extensions can be used as powerful tools for cyber attacks. Even extensions that look useful or harmless can secretly steal data. Similar risks have been seen in other browser security issues, such as Google Fixes Actively Exploited Chrome Zero-Day Vulnerability, which shows how attackers keep finding new ways to target users. Users should stay careful, install only trusted extensions, and regularly clean their browser. A smaller number of safe extensions always improves security and reduces risk.

You may also like

Adblock Detected

Please support us by disabling your AdBlocker extension from your browsers for our website.