Full Breakdown
Surge of Malicious Chrome Extensions Poses Data Theft Risks
4/16/2026, 12:38:50 AM
Discovery of Malicious Extensions
A recent investigation by the supply chain security firm Socket has uncovered 108 malicious Chrome extensions available on the Chrome Web Store, collectively downloaded over 20,000 times. These extensions, masquerading as games, utilities, and other tools, are designed to stealthily steal user data and inject advertisements into web pages. Notably, despite being developed by five different entities, all the stolen data is directed to a single command-and-control (C2) server, indicating a coordinated cyber operation.
Notable Malicious Extensions
Among the identified extensions, several have garnered significant user installations, including:
- Web Client for TikTok – 2,000+ installs
- Web Client for Telegram - Teleside – 1,000+ installs
- YouSide - Youtube Sidebar – 1,000+ installs
- Formula Rush Racing Game – 1,000+ installs
- Page Auto Refresh – 1,000+ installs
These extensions appear to function normally, making it difficult for users to detect their malicious intent. However, they are capable of hijacking Telegram accounts, adding backdoors to browsers, and stealing critical Google identifiers, including users' Gmail addresses and profile pictures.
Data Theft Concerns
The most alarming aspect of these extensions is their ability to harvest Google "sub" IDs, which are unique identifiers assigned to user accounts. This identifier remains constant even if users change their passwords or email addresses, allowing cybercriminals to create a persistent profile of individuals' online activities. This capability raises significant privacy concerns, as it enables hackers to track users across different platforms and potentially exploit them in future scams.
Recommendations for Users
To mitigate the risks associated with malicious extensions, users are advised to exercise caution when downloading new browser add-ons. It is recommended to:
- Stick to well-known extensions from reputable developers.
- Review user ratings and permissions before installation, particularly for extensions requesting extensive data access.
- Enable Enhanced Safe Browsing in Chrome's security settings for real-time protection against untrusted extensions.
- Regularly audit installed extensions and remove any that are no longer in use.
Additionally, employing robust antivirus software can provide an extra layer of security against potential malware installations.
Conclusion
The proliferation of malicious Chrome extensions highlights the vulnerabilities inherent in browser security. While extensions can enhance user experience, the risks associated with unverified add-ons necessitate a cautious approach. Regular monitoring and informed decision-making are essential to safeguard personal data and maintain online security.
