Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Best Prime Day robot vacuum deals of 2026: Dreame, Shark, and more

Top 10 Best TV Shows of 2026 So Far

Meet Oren Uziel, the mastermind behind Spider Noir and the series whisperer

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Over 100 fake Chrome extensions found hijacking sessions, credential stealing, ad injections
Celebrities

Over 100 fake Chrome extensions found hijacking sessions, credential stealing, ad injections

By May 20, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 20, 2025Ravi LakshmananCredentials/Browser Security

The unknown threat actor has been equipped with seemingly benign utility since February 2024, but is attributed to creating several malicious Chrome browser extensions that incorporate hidden features to remove data, receive commands, and execute arbitrary code.

“The actor will create websites pose as legitimate services, productivity tools, advertising and media creation assistants, VPN services, banks, and more, and instruct them to install malicious extensions that correspond to Google’s Chrome Web Store (CWS).

The browser add-on appears to provide advertised features, but also enables phishing with credentials and cookie theft, session hijacking, ad injection, malicious redirects, traffic operations, and DOM operations.

Cybersecurity

Another factor that works in your advantage with extensions is that they are configured to grant excessive permissions via the Manifest.json file.

It is also known that extensions rely on the “OnReset” event handler of temporary document object model (DOM) elements to bypass content security policies (CSP), possibly to execute code.

Some identified lure websites will tempt users to download and install extensions by impersonating legitimate products and services such as Deepseek, Manus, Debank, Fortivpn, and site statistics. The add-on goes to harvesting browser cookies, retrieves any scripts from the remote server and sets up a Websocket connection that acts as a network proxy for traffic routing.

Currently, there is no visibility into the way victims are redirected to fake sites, but Domaintools told the publication it could include regular methods such as phishing and social media.

“They have appeared in both Chrome Web stores and have adjacent websites, so they can return from the results of searches within the Chrome Store as a result of normal web searches,” the company said. “Many of the lure websites used Facebook tracking IDs, which strongly suggests that Facebook/meta apps be revered in some way to attract site visitors.

At the time of writing, we don’t know who is behind the campaign, but the threat actors have over 100 fake websites and malicious Chrome extensions set up. Google has removed the extension.

Cybersecurity

To mitigate risk, users are encouraged to stick to a verified developer before downloading the extension. Review requested permissions, review reviews, and refrain from using visual extensions.

That said, it is worth keeping in mind that filtering negative user feedback can manipulate and artificially inflate ratings.

In an analysis published later last month, domainools found evidence of an extension that is pretending to be DeepSeek, redirecting users who provide low ratings (1-3 stars) for AI-chat-bot’s private feedback form[.]Pro Domain sends those that offer high ratings (4-5 stars) to the official Chrome Web Store review page.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleIt was worth more than $1 billion, so Microsoft-Backed Builder.ai is short on money
Next Article Immerse LDN: awaken Tutankhamun

Related Posts

Rocket Williams and Helen Lasichan appear at the Louis Vuitton men’s show

June 24, 2026

Kristen Stewart shows off Chanel cruise style at Biarritz Film Festival

June 24, 2026

Ellie Goulding wears Matiere Fécairess at the Serpentine Summer Parry

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Best Prime Day robot vacuum deals of 2026: Dreame, Shark, and more

Top 10 Best TV Shows of 2026 So Far

Meet Oren Uziel, the mastermind behind Spider Noir and the series whisperer

Best Breville Deal: $279.96 off Breville Barista Pro on Prime Day

Trending Posts

ADE Pro Introduces New 30th Anniversary Speakers: See the Lineup

June 25, 2026

Alison Wonderland selected for FIFA World Cup honors

June 25, 2026

RÜFÜS DU SOL makes EDM history at Madison Square Garden

June 25, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.