{"id":233582,"date":"2026-04-14T04:35:00","date_gmt":"2026-04-14T08:35:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/04\/14\/108-malicious-chrome-extensions-steal-google-and-telegram-data-affecting-20000-users\/"},"modified":"2026-04-20T20:00:08","modified_gmt":"2026-04-21T00:00:08","slug":"108-malicious-chrome-extensions-steal-google-and-telegram-data-affecting-20000-users","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/04\/14\/108-malicious-chrome-extensions-steal-google-and-telegram-data-affecting-20000-users\/","title":{"rendered":"108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/108-malicious-chrome-extensions-steal.html\">108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/108-malicious-chrome-extensions-steal.html\">https:\/\/thehackernews.com\/2026\/04\/108-malicious-chrome-extensions-steal.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-04-14 04:35:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Apr 14, 2026<\/span><\/span><span class=\"p-tags\">Data Theft \/ Browser Security<\/span><\/p>\n<p>Cybersecurity researchers have discovered a new campaign in which a cluster of 108 Google Chrome extensions has been found to communicate with the same command-and-control (C2) infrastructure with the goal of collecting user data and enabling browser-level abuse by injecting ads and arbitrary JavaScript code into every web page\u00a0visited.<\/p>\n<p>According to Socket, the extensions (complete list here) are published under five distinct publisher identities \u2013 Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt \u2013 and have collectively amassed about 20,000 installs in the Chrome Web\u00a0Store.<\/p>\n<p>&#8220;All 108 route stolen credentials, user identities, and browsing data to servers controlled by the same operator,&#8221; security researcher Kush\u00a0Pandya said in an\u00a0analysis.\u00a0<\/p>\n<p>Of these, 54 add-ons steal Google account identity via OAuth2, 45 extensions contain a universal backdoor that opens arbitrary URLs as soon as the browser is started, and the remaining ones engage in a variety of malicious behaviors\u00a0&#8211;<\/p>\n<ul>\n<li>Exfiltrate Telegram Web sessions every 15 seconds<\/li>\n<li>Strip YouTube and TikTok security headers (i.e., Content Security Policy, X-Frame-Options, and CORS) and inject gambling overlays and ads<\/li>\n<li>Inject content scripts into every page the user visits<\/li>\n<li>Proxy all translation requests through the threat actor&#8217;s server<\/li>\n<\/ul>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"1280\" data-original-width=\"1280\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCID6WdCf6NahLEXNxG3NBdHR_nMToGiNP1RUeIAFXerxXS2XzGKaoloqKKTd99YEZPnsRSoyE3wzEs3NTO_Q-cfGclNOO76hxbLwVvbeQTP2MD0Gf1TFEKEfKecz2VOuYOSz5bBIbyZ11d_Cql_a6VY90d9lQVxwnDjE4P4JGZu-snpVRd4KJw9Job0bS\/s1600\/tele.jpg\"\/><\/p>\n<p>In an attempt to lend a veneer of legitimacy, the identified extensions masquerade as Telegram sidebar clients, slot machine and Keno games, YouTube and TikTok enhancers, text translation tools, and page utilities. The\u00a0advertised functionality is diverse, aiming to cast a wide net, while sharing the same\u00a0backend.<\/p>\n<p>Unbeknownst to the users, however, malicious code running in the background captures session information, injects arbitrary scripts, and opens URLs of the attacker&#8217;s\u00a0choosing.<\/p>\n<p>Some of the identified extensions are listed below\u00a0&#8211;<\/p>\n<ul>\n<li>Telegram Multi-account (ID: obifanppcpchlehkjipahhphbcbjekfa),&#8230;<\/li>\n<\/ul>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/108-malicious-chrome-extensions-steal.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users https:\/\/thehackernews.com\/2026\/04\/108-malicious-chrome-extensions-steal.html Publish Date:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":233583,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiEOmjr311c0yBDI593joFXQLaRdpm6DY67lbFv83YcYlRHaJkpocwXjDZDsV9F9DM-SavZwCOZ-fg10ncUJyW3ODlfBjqG6aK_ytdBfvXFGLswxeJ69oiZXfhGKdCgVO0Angg_qlYB6oAZYo-JQRKn4toBGWcS7OTDwPV0rkus7eNw-9BllIGJa2nkeKXn\/s1600\/chrome-telegram.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,34],"class_list":["post-233582","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-threat-actor"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/233582"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=233582"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/233582\/revisions"}],"predecessor-version":[{"id":233584,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/233582\/revisions\/233584"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/233583"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=233582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=233582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=233582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}