According to Bleeping Computer, over 100 malicious extensions have been discovered in the official Chrome Web Store, actively engaged in stealing Google OAuth2 Bearer tokens, deploying backdoors, and conducting ad fraud. These extensions were part of a coordinated campaign identified by application security company Socket, utilizing shared command-and-control infrastructure.The threat actor published these malicious extensions under five different publisher identities, spanning various categories such as Telegram clients, games, YouTube and TikTok enhancers, translation tools, and utilities. The campaign's backend infrastructure, hosted on a Contabo VPS, managed session hijacking, identity collection, command execution, and monetization. A significant cluster of 78 extensions injected attacker-controlled HTML, while 54 others used "chrome.identity.getAuthToken" to harvest user data including email, name, profile picture, and Google account ID, along with the crucial OAuth2 Bearer token. Another 45 extensions acted as backdoors, fetching commands from the C2 and opening arbitrary URLs without user interaction. One particularly severe extension was found to steal Telegram Web sessions every 15 seconds by extracting data from "localStorage" and the session token, even capable of swapping a victim's Telegram account.Evidence suggests a Russian malware-as-a-service operation, underscoring the evolving landscape of cyber threats. While Socket has notified Google, many of these extensions remained available at the time of reporting, emphasizing the need for users to remain vigilant. Source: Bleeping Computer
Data Security, Application security

Over 100 malicious Chrome extensions steal tokens, deploy backdoors

(Adobe Stock)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



