Close Menu
    What's Hot

    Ye and Travis Scott Concerts Canceled in Italy Over Security Fears

    Middle East on Edge as Trump Mulls Decision About Iran Deal

    When War Breaks Out Over the Family Business, They Get the Call

    Facebook X (Twitter) Instagram
    Trending
    • Ye and Travis Scott Concerts Canceled in Italy Over Security Fears
    • Middle East on Edge as Trump Mulls Decision About Iran Deal
    • When War Breaks Out Over the Family Business, They Get the Call
    • How You Treat Contractors Can Make or Break Your Brand
    • Keychron K2 HE Concrete Edition Review: Rock-Solid Typing
    • Historic cattle shortages push US beef prices to record highs
    • Vaibhav Sooryavanshi: Is IPL wonderkid, 15, best T20 opener in the world and do India have to pick him for England series? | Cricket News
    • ‘Backrooms’ Takes You Deeper Inside the Internet’s Most Uncanny Horror Myth
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users

    adminBy adminApril 14, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 14, 2026Data Theft / Browser Security

    108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users

    Cybersecurity researchers have discovered a new campaign in which a cluster of 108 Google Chrome extensions has been found to communicate with the same command-and-control (C2) infrastructure with the goal of collecting user data and enabling browser-level abuse by injecting ads and arbitrary JavaScript code into every web page visited.

    According to Socket, the extensions are published under five distinct publisher identities – Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt – and have collectively amassed about 20,000 installs in the Chrome Web Store.

    “All 108 route stolen credentials, user identities, and browsing data to servers controlled by the same operator,” security researcher Kush Pandya said in an analysis. 

    Cybersecurity

    Of these, 54 add-ons steal Google account identity via OAuth2, 45 extensions contain a universal backdoor that opens arbitrary URLs as soon as the browser is started, and the remaining ones engage in a variety of malicious behaviors –

    • Exfiltrate Telegram Web sessions every 15 seconds
    • Strip YouTube and TikTok security headers (i.e., Content Security Policy, X-Frame-Options, and CORS) and inject gambling overlays and ads
    • Inject content scripts into every page the user visits
    • Proxy all translation requests through the threat actor’s server

    In an attempt to lend a veneer of legitimacy, the identified extensions masquerade as Telegram sidebar clients, slot machine and Keno games, YouTube and TikTok enhancers, text translation tools, and page utilities. The advertised functionality is diverse, aiming to cast a wide net, while sharing the same backend.

    Unbeknownst to the users, however, malicious code running in the background captures session information, injects arbitrary scripts, and opens URLs of the attacker’s choosing.

    Some of the identified extensions are listed below –

    • Telegram Multi-account (ID: obifanppcpchlehkjipahhphbcbjekfa), which extracts the user_auth token used by Telegram Web and exfiltrates the data to a remote server. It can also overwrite localStorage with threat actor-supplied session data and force-load the messaging application, effectively replacing the victim’s active Telegram session with the threat actor’s chosen session.
    • Web Client for Telegram – Teleside (ID: mdcfennpfgkngnibjbpnpaafcjnhcjno), which strips Telegram’s security headers and injects scripts to steal Telegram sessions.
    • Formula Rush Racing Game (ID: akebbllmckjphjiojeioooidhnddnplj), which steals the user’s Google account identity the first time the victim clicks the sign-in button. This includes details like email, full name, profile picture URL, and Google account identifier.
    Cybersecurity

    “Five extensions use Chrome’s declarativeNetRequest API to strip security headers from target sites before the page loads,” Socket said. “All 108 malicious extensions share the same backend, hosted at 144.126.135[.]238.”

    It’s currently not known who is behind the policy-violating extensions. However, an analysis of source code has uncovered Russian language comments across several add-ons.

    Users who have installed any of the extensions are advised to remove them with immediate effect and log out of all Telegram Web sessions from the Telegram mobile app.

    Affecting Chrome data extensions Google malicious steal Telegram users
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleSchool shooting in Turkey leaves 16 wounded, governor says
    Next Article The Best Mattresses for Stomach Sleepers, According to a Sleep Science Coach (2026)
    admin
    • Website

    Related Posts

    Nvidia: Data Centers Made It Great, Physical AI Could Make It Generational (NASDAQ:NVDA)

    May 30, 2026

    PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

    May 30, 2026

    Microsoft Points to Quincy to Counter Data Center Backlash—But Can It Be Repeated?

    May 29, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Ye and Travis Scott Concerts Canceled in Italy Over Security Fears

    Middle East on Edge as Trump Mulls Decision About Iran Deal

    When War Breaks Out Over the Family Business, They Get the Call

    How You Treat Contractors Can Make or Break Your Brand

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by