Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Hackers are actively exploiting bugs in cPanel, which is used by millions of websites.

OpenAI announces new advanced security for ChatGPT accounts, including partnership with Yubico

Elon Musk testifies that xAI trained Grok on OpenAI model

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Over 100 fake Chrome extensions found hijacking sessions, credential stealing, ad injections
Identity

Over 100 fake Chrome extensions found hijacking sessions, credential stealing, ad injections

By May 20, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 20, 2025Ravi LakshmananCredentials/Browser Security

The unknown threat actor has been equipped with seemingly benign utility since February 2024, but is attributed to creating several malicious Chrome browser extensions that incorporate hidden features to remove data, receive commands, and execute arbitrary code.

“The actor will create websites pose as legitimate services, productivity tools, advertising and media creation assistants, VPN services, banks, and more, and instruct them to install malicious extensions that correspond to Google’s Chrome Web Store (CWS).

The browser add-on appears to provide advertised features, but also enables phishing with credentials and cookie theft, session hijacking, ad injection, malicious redirects, traffic operations, and DOM operations.

Cybersecurity

Another factor that works in your advantage with extensions is that they are configured to grant excessive permissions via the Manifest.json file.

It is also known that extensions rely on the “OnReset” event handler of temporary document object model (DOM) elements to bypass content security policies (CSP), possibly to execute code.

Some identified lure websites will tempt users to download and install extensions by impersonating legitimate products and services such as Deepseek, Manus, Debank, Fortivpn, and site statistics. The add-on goes to harvesting browser cookies, retrieves any scripts from the remote server and sets up a Websocket connection that acts as a network proxy for traffic routing.

Currently, there is no visibility into the way victims are redirected to fake sites, but Domaintools told the publication it could include regular methods such as phishing and social media.

“They have appeared in both Chrome Web stores and have adjacent websites, so they can return from the results of searches within the Chrome Store as a result of normal web searches,” the company said. “Many of the lure websites used Facebook tracking IDs, which strongly suggests that Facebook/meta apps be revered in some way to attract site visitors.

At the time of writing, we don’t know who is behind the campaign, but the threat actors have over 100 fake websites and malicious Chrome extensions set up. Google has removed the extension.

Cybersecurity

To mitigate risk, users are encouraged to stick to a verified developer before downloading the extension. Review requested permissions, review reviews, and refrain from using visual extensions.

That said, it is worth keeping in mind that filtering negative user feedback can manipulate and artificially inflate ratings.

In an analysis published later last month, domainools found evidence of an extension that is pretending to be DeepSeek, redirecting users who provide low ratings (1-3 stars) for AI-chat-bot’s private feedback form[.]Pro Domain sends those that offer high ratings (4-5 stars) to the official Chrome Web Store review page.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleIt was worth more than $1 billion, so Microsoft-Backed Builder.ai is short on money
Next Article Immerse LDN: awaken Tutankhamun

Related Posts

PyTorch Lightning and Intercom Client Suffer Supply Chain Attack to Steal Credentials

April 30, 2026

SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories

April 30, 2026

New Python backdoor uses tunneling service to steal browser and cloud credentials

April 30, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Hackers are actively exploiting bugs in cPanel, which is used by millions of websites.

OpenAI announces new advanced security for ChatGPT accounts, including partnership with Yubico

Elon Musk testifies that xAI trained Grok on OpenAI model

Robhy Bustami of BioticsAI maintains momentum and morale during the long road to FDA approval

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.