Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Google adds Rust-based DNS parser to Pixel 10 modems for added security

The science of getting there

Mirax Android RAT turns devices into SOCKS5 proxies and reaches 220,000 via meta ads

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » 108 malicious Chrome extensions steal Google and Telegram data, affecting 20,000 users
Identity

108 malicious Chrome extensions steal Google and Telegram data, affecting 20,000 users

By April 14, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 14, 2026Data theft / browser security

Cybersecurity researchers have discovered a new campaign in which a cluster of 108 Google Chrome extensions were found to be communicating with the same command-and-control (C2) infrastructure with the goal of harvesting user data and enabling browser-level exploits by injecting ads and arbitrary JavaScript code into every web page visited.

According to Socket, the extension is published under five different publisher IDs: Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt, and has amassed about 20,000 total installs in the Chrome Web Store.

“All 108 sent stolen credentials, user IDs, and browsing data to servers controlled by the same operator,” security researcher Kush Pandya said in an analysis.

Of these, 54 add-ons steal Google account identities via OAuth2, 45 extensions contain a universal backdoor that opens arbitrary URLs as soon as the browser is started, and the remaining add-ons perform various malicious behaviors.

Extract Telegram web sessions every 15 seconds Remove YouTube and TikTok security headers (Content Security Policy, X-Frame Options, CORS) and insert gambling overlays and ads Inject content scripts into every page a user visits Proxy all translation requests through the threat actor’s servers

In order to appear legitimate, the identified extensions pretend to be Telegram sidebar clients, slot machines and Keno games, YouTube and TikTok enhancers, text translation tools, and page utilities. The advertised features are diverse and aim to cast a wide net while sharing the same backend.

However, unnoticed by the user, malicious code running in the background captures session information, injects arbitrary script, and opens a URL of the attacker’s choice.

Some of the extensions identified are listed below.

Telegram multi-account (ID: obifanppcpchlehkjipahhphbcbjekfa). Extract the user_auth token used by Telegram Web and extract the data to a remote server. It can also overwrite localStorage with session data provided by the threat actor, forcing the messaging application to load, effectively replacing the victim’s active Telegram session with a session of the threat actor’s choosing. Web client for Telegram – Teleside (ID: mdcfennpfgkngnibjbpnpaafcjnhcjno). Injects a script that removes Telegram security headers and steals Telegram sessions. Formula Rush Racing Game (ID: akebbllmckjphjiojeiooooidhnddnplj). It steals the user’s Google Account ID the first time the victim clicks the sign-in button. This includes details such as email, full name, profile picture URL, and Google Account ID.

“The five extensions use Chrome’s declarativeNetRequest API to remove security headers from the target site before the page loads,” Socket said. “All 108 malicious extensions share the same backend, hosted at 144.126.135.[.]238″

It is currently unclear who is behind the policy-violating extension. However, analysis of the source code revealed that some add-ons contained comments in Russian.

Users who have installed any of the extensions are advised to immediately remove the extension and log out of all Telegram web sessions from the Telegram mobile app.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHow quantum science will shape our future
Next Article Record-breaking 2025 season hints at climate threats

Related Posts

Google adds Rust-based DNS parser to Pixel 10 modems for added security

April 14, 2026

Mirax Android RAT turns devices into SOCKS5 proxies and reaches 220,000 via meta ads

April 14, 2026

Analysis of 216 million security findings reveals 4x increase in critical risks (2026 report)

April 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Google adds Rust-based DNS parser to Pixel 10 modems for added security

The science of getting there

Mirax Android RAT turns devices into SOCKS5 proxies and reaches 220,000 via meta ads

X-SEED project: Supercritical membraneless electrolysis

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.