# Massive Chrome Extension Campaign Targeting 20,000 Users Harvests Google Credentials and Hijacks Telegram Sessions


A coordinated malware operation leveraging 108 malicious Google Chrome extensions has compromised the security of approximately 20,000 users across multiple browsers, exposing sensitive credentials and enabling unauthorized access to popular messaging platforms. The campaign, uncovered by cybersecurity researchers, demonstrates the persistent vulnerability of browser extension ecosystems to supply-chain compromise and the continued sophistication of credential-harvesting operations targeting high-value accounts.


## The Scope and Scale of the Attack


The sheer number of compromised extensions—108 distinct malicious plugins—suggests a carefully orchestrated campaign designed to evade detection through distribution diversity. Rather than relying on a single malicious extension that might quickly be flagged and removed, the threat actors instead cast a wide net across the Chrome Web Store and other distribution channels, each extension serving as an independent vector for data exfiltration.


The scale reaches approximately 20,000 affected users, though the actual number may be significantly higher given the challenges researchers face in discovering all compromised installations. Each extension functioned as a separate entity, yet all reported collected data to a central command infrastructure, indicating unified orchestration and purpose across the campaign.


## Credential Harvesting and Telegram Session Hijacking


The malware's primary objectives centered on two lucrative targets: Google account credentials and active Telegram sessions. Both represent high-value assets in the cybercriminal underground, enabling attackers to gain persistent access to email systems, cloud storage, and encrypted messaging platforms where victims often conduct sensitive personal and professional communication.


Google credentials provide attackers with a master key to a victim's digital life. Once compromised, these credentials unlock:

  • Email access and account recovery mechanisms
  • Google Drive and cloud storage contents
  • YouTube accounts and viewing history
  • Connected third-party services authenticated via Google Sign-in
  • Account recovery options for other services relying on email verification

  • Telegram session hijacking proves particularly valuable in espionage and fraud scenarios. By compromising active sessions rather than stealing passwords, attackers bypass two-factor authentication and maintain persistence even if the victim changes their password, continuing to intercept messages and monitor communications until the victim manually logs out or revokes sessions through other devices.


    ## Technical Attack Mechanisms


    The malicious extensions employed multiple techniques to accomplish their objectives:


    Credential Interception: The extensions monitored user activity across the web, intercepting login credentials entered into Google's authentication system. This likely involved injecting JavaScript into login pages or monitoring network traffic to capture credentials in transit before encryption, a sophisticated but well-understood technique in advanced credential-stealing malware.


    Session Cookie Theft: Rather than relying solely on password capture, the malware also targeted authentication cookies and tokens, which provide immediate access to accounts without requiring passwords. This approach proves more reliable than credential theft in modern environments where users employ password managers and the browser handles encryption automatically.


    Ad Injection and Script Injection: Beyond credential harvesting, the extensions injected unwanted advertisements and malicious scripts into web pages visited by compromised users. This dual-purpose capability served multiple attacker objectives—generating advertising revenue while simultaneously tracking user behavior and creating additional attack surface for exploitation.


    Centralized Command and Control: All 108 extensions reported their collected data to the same central infrastructure point, enabling the threat actors to aggregate stolen credentials, coordinate attacks, and maintain consistent control across the entire operation.


    ## The Browser Extension Vulnerability Problem


    This campaign illustrates a critical structural vulnerability in how browser extension ecosystems operate. Extensions receive broad permissions to monitor user activity, access stored data, and modify web content—capabilities necessary for legitimate functionality but equally dangerous when granted to malicious actors.


    The Chrome Web Store's vetting process, while improved in recent years, remains insufficient to catch sophisticated malware campaigns that:

  • Distribute functionality across numerous extensions to reduce individual risk profiles
  • Implement code obfuscation and delayed activation to evade automated scanning
  • Masquerade as legitimate productivity tools or security utilities
  • Gradually expand permissions or malicious behavior post-installation through updates

  • The ability to update extensions silently in the background further compounds the problem, enabling threat actors to deploy final-stage malware weeks or months after an extension's initial installation, after the installer has gained user trust and legitimate reviews.


    ## User Impact and Risk Assessment


    Affected users face multiple overlapping risks depending on which data the attackers obtained:


    Immediate Account Compromise: Stolen Google credentials enable immediate account takeover, allowing attackers to change passwords, enable account recovery mechanisms tied to attacker-controlled email addresses, and establish persistent access through secondary authentication methods.


    Financial Exposure: Access to email and Google accounts enables attackers to identify financial accounts, request password resets, and intercept verification codes, putting victims at risk for banking, cryptocurrency, and investment account compromise.


    Communication Surveillance: Hijacked Telegram sessions provide access to historical message content and ongoing surveillance of future communications, compromising both privacy and operational security for individuals in sensitive professions.


    Identity Theft: Stolen credentials combined with email access enable comprehensive identity theft operations, where attackers impersonate victims to establish accounts, apply for credit, or conduct social engineering attacks against the victim's contacts.


    ## Recommendations for Users and Organizations


    Immediate Actions:

  • Review installed Chrome extensions and remove any unfamiliar or unused extensions
  • Change Google account passwords from a clean device
  • Enable advanced protection on Google accounts if available
  • Review Google account security settings and active sessions, terminating any unrecognized logins
  • Log out of Telegram from all devices and review active sessions

  • Ongoing Protection:

  • Limit Chrome extensions to officially published tools from verified developers with strong review histories
  • Regularly audit installed extensions for necessity and legitimacy
  • Enable Chrome's safety browsing features and malware protection
  • Consider using a password manager to eliminate manual password entry on compromised systems
  • Use separate browser profiles or isolated browsing environments for sensitive activities requiring authentication

  • Organizations should consider deploying browser management policies that restrict which extensions users may install, implement additional monitoring of browser extension activity, and educate staff about extension security risks during security awareness training.


    ## HackWire Analysis


    The discovery of this 108-extension malware campaign reflects a broader evolution in malware distribution strategies. Rather than racing to compromise a single highly-popular extension, modern threat actors employ patience and diversity, distributing malicious functionality across numerous lesser-known extensions to maximize scale while minimizing the risk of wholesale removal. The coordination with centralized infrastructure suggests sophisticated threat actors—potentially state-sponsored groups or well-organized criminal syndicates—capable of managing complex multi-extension campaigns at scale. Until browser vendors implement more granular permission models and deployment verification mechanisms, users remain vulnerable to campaigns of this magnitude and sophistication.