Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

With fewer ordinances, seminaries have found ways to serve young professionals in other fields

Beer 2.0: Meme Coin Brewing Something Big in Solana

Wall Street Ponke launches AI tools, learning hubs and over $300,000 in hours

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Over 100 fake Chrome extensions found hijacking sessions, credential stealing, ad injections
Identity

Over 100 fake Chrome extensions found hijacking sessions, credential stealing, ad injections

userBy userMay 20, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 20, 2025Ravi LakshmananCredentials/Browser Security

The unknown threat actor has been equipped with seemingly benign utility since February 2024, but is attributed to creating several malicious Chrome browser extensions that incorporate hidden features to remove data, receive commands, and execute arbitrary code.

“The actor will create websites pose as legitimate services, productivity tools, advertising and media creation assistants, VPN services, banks, and more, and instruct them to install malicious extensions that correspond to Google’s Chrome Web Store (CWS).

The browser add-on appears to provide advertised features, but also enables phishing with credentials and cookie theft, session hijacking, ad injection, malicious redirects, traffic operations, and DOM operations.

Cybersecurity

Another factor that works in your advantage with extensions is that they are configured to grant excessive permissions via the Manifest.json file.

It is also known that extensions rely on the “OnReset” event handler of temporary document object model (DOM) elements to bypass content security policies (CSP), possibly to execute code.

Some identified lure websites will tempt users to download and install extensions by impersonating legitimate products and services such as Deepseek, Manus, Debank, Fortivpn, and site statistics. The add-on goes to harvesting browser cookies, retrieves any scripts from the remote server and sets up a Websocket connection that acts as a network proxy for traffic routing.

Currently, there is no visibility into the way victims are redirected to fake sites, but Domaintools told the publication it could include regular methods such as phishing and social media.

“They have appeared in both Chrome Web stores and have adjacent websites, so they can return from the results of searches within the Chrome Store as a result of normal web searches,” the company said. “Many of the lure websites used Facebook tracking IDs, which strongly suggests that Facebook/meta apps be revered in some way to attract site visitors.

At the time of writing, we don’t know who is behind the campaign, but the threat actors have over 100 fake websites and malicious Chrome extensions set up. Google has removed the extension.

Cybersecurity

To mitigate risk, users are encouraged to stick to a verified developer before downloading the extension. Review requested permissions, review reviews, and refrain from using visual extensions.

That said, it is worth keeping in mind that filtering negative user feedback can manipulate and artificially inflate ratings.

In an analysis published later last month, domainools found evidence of an extension that is pretending to be DeepSeek, redirecting users who provide low ratings (1-3 stars) for AI-chat-bot’s private feedback form[.]Pro Domain sends those that offer high ratings (4-5 stars) to the official Chrome Web Store review page.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleIt was worth more than $1 billion, so Microsoft-Backed Builder.ai is short on money
Next Article Immerse LDN: awaken Tutankhamun
user
  • Website

Related Posts

Hazy Hawk Exploites DNS Records hijack CDC to hijack CDC, the corporate domain for malware delivery

May 20, 2025

Sidewinder hit South Asia with old office flaws and custom malware

May 20, 2025

AWS default IAM role is known to allow for lateral movement and cross-service exploitation

May 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

With fewer ordinances, seminaries have found ways to serve young professionals in other fields

Beer 2.0: Meme Coin Brewing Something Big in Solana

Wall Street Ponke launches AI tools, learning hubs and over $300,000 in hours

Thousands of Gaza children face imminent deaths under the siege of Israel: United Nations | Israeli-Palestinian conflict news

Trending Posts

Thousands of Gaza children face imminent deaths under the siege of Israel: United Nations | Israeli-Palestinian conflict news

May 20, 2025

British government suspends free trade talks with Israel over the Gaza War | Israeli-Palestinian conflict news

May 20, 2025

UEFA Europa League Final: Man UTD vs Tottenham – Start, Team News, Lineup | Football News

May 20, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Beer 2.0: Meme Coin Brewing Something Big in Solana

Wall Street Ponke launches AI tools, learning hubs and over $300,000 in hours

New Scanner Technology in Stock Market Guide shows historical track record for each trade setup found

Which casino games will be the biggest in the future?

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.