108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内。首先,我需要快速浏览文章,抓住主要信息。文章讲的是发现了108个Chrome扩展程序,它们被用来窃取用户数据和进行浏览器层面的滥用。这些扩展程序通过同一个命令控制基础设施运作,窃取Google账户信息、注入广告和JavaScript代码。 接下来,我注意到这些扩展程序伪装成各种合法工具,比如Telegram客户端、游戏和翻译工具。它们通过OAuth2窃取Google账户身份,并且在后台运行恶意代码,捕获会话信息。此外,这些扩展还剥离了YouTube和TikTok的安全头,注入赌博覆盖层和广告。 文章还提到,所有108个扩展共享同一个后端服务器,并且在代码中发现了俄语评论。目前还不清楚是谁在背后操纵这些扩展程序。最后,建议用户立即删除这些扩展,并从Telegram移动应用中注销所有Web会话。 现在我要把这些信息浓缩到100字以内。需要包括发现的扩展数量、它们的功能、伪装成合法工具、窃取数据、注入广告和JavaScript代码、后端服务器以及建议删除扩展等关键点。 可能的结构是:描述发现的恶意Chrome扩展数量及其目的,伪装成合法工具,窃取数据并注入广告/脚本,所有共享同一后端,并建议删除。 这样应该能在100字以内准确传达文章的核心内容。 </think> 研究人员发现108款恶意Chrome扩展程序通过伪装成合法工具窃取用户数据并注入广告及脚本代码。这些扩展共享同一后端服务器,并利用OAuth2等技术窃取Google账户信息及Telegram会话数据。建议用户立即删除相关扩展以防止进一步风险。 2026-4-14 08:35:0 Author: thehackernews.com(查看原文) 阅读量:21 收藏

Data Theft / Browser Security

Cybersecurity researchers have discovered a new campaign in which a cluster of 108 Google Chrome extensions has been found to communicate with the same command-and-control (C2) infrastructure with the goal of collecting user data and enabling browser-level abuse by injecting ads and arbitrary JavaScript code into every web page visited.

According to Socket, the extensions are published under five distinct publisher identities – Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt – and have collectively amassed about 20,000 installs in the Chrome Web Store.

"All 108 route stolen credentials, user identities, and browsing data to servers controlled by the same operator," security researcher Kush Pandya said in an analysis. 

Of these, 54 add-ons steal Google account identity via OAuth2, 45 extensions contain a universal backdoor that opens arbitrary URLs as soon as the browser is started, and the remaining ones engage in a variety of malicious behaviors -

  • Exfiltrate Telegram Web sessions every 15 seconds
  • Strip YouTube and TikTok security headers (i.e., Content Security Policy, X-Frame-Options, and CORS) and inject gambling overlays and ads
  • Inject content scripts into every page the user visits
  • Proxy all translation requests through the threat actor's server

In an attempt to lend a veneer of legitimacy, the identified extensions masquerade as Telegram sidebar clients, slot machine and Keno games, YouTube and TikTok enhancers, text translation tools, and page utilities. The advertised functionality is diverse, aiming to cast a wide net, while sharing the same backend.

Unbeknownst to the users, however, malicious code running in the background captures session information, injects arbitrary scripts, and opens URLs of the attacker's choosing.

Some of the identified extensions are listed below -

  • Telegram Multi-account (ID: obifanppcpchlehkjipahhphbcbjekfa), which extracts the user_auth token used by Telegram Web and exfiltrates the data to a remote server. It can also overwrite localStorage with threat actor-supplied session data and force-load the messaging application, effectively replacing the victim's active Telegram session with the threat actor's chosen session.
  • Web Client for Telegram - Teleside (ID: mdcfennpfgkngnibjbpnpaafcjnhcjno), which strips Telegram's security headers and injects scripts to steal Telegram sessions.
  • Formula Rush Racing Game (ID: akebbllmckjphjiojeioooidhnddnplj), which steals the user's Google account identity the first time the victim clicks the sign-in button. This includes details like email, full name, profile picture URL, and Google account identifier.

"Five extensions use Chrome's declarativeNetRequest API to strip security headers from target sites before the page loads," Socket said. "All 108 malicious extensions share the same backend, hosted at 144.126.135[.]238."

It's currently not known who is behind the policy-violating extensions. However, an analysis of source code has uncovered Russian language comments across several add-ons.

Users who have installed any of the extensions are advised to remove them with immediate effect and log out of all Telegram Web sessions from the Telegram mobile app.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/04/108-malicious-chrome-extensions-steal.html
如有侵权请联系:admin#unsafe.sh