# 152 Malicious Chrome Extensions Pose Widespread Threat: Adware, Traffic Fraud, and Data Harvesting Scheme Exposes 105,000 Users
Cybersecurity researchers have uncovered a sprawling campaign deploying 152 malicious Google Chrome extensions across 38 separate publisher accounts, collectively installed over 105,000 times. The extensions—disguised as wallpaper customization tools—operate an elaborate scheme combining adware distribution, user data harvesting, and sophisticated traffic attribution fraud designed to deceive advertising networks and inflate affiliate commissions.
## The Threat
Security researchers at Socket identified a coordinated network of extensions operating under the guise of popular anime, gaming, and automotive wallpaper add-ons. Among the identified extensions are titles such as Neymar - Football Live Wallpaper, Satoru Gojo Manga Live Wallpaper, Hello Kitty Wallpapers HD New Tab, and Spider-Man Miles Morales Swing Live Wallpaper—names designed to appeal to pop culture enthusiasts and casual Chrome users.
Despite their innocent-sounding names and widespread distribution, these extensions execute a multi-layered attack:
The 105,000 cumulative installations across the cluster represent significant user exposure to these malicious practices, with the extensions distributed through three primary backend domains: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com.
## Background and Context
Chrome extensions remain one of the most effective vectors for distributing unwanted programs (PUPs) due to their privileged access to browser functionality and user browsing behavior. Extensions can operate with minimal oversight once installed, making the Chrome Web Store a recurring target for threat actors seeking legitimate-appearing distribution channels.
This campaign distinguishes itself through scale and sophistication. Rather than deploying a single malicious extension, the operators maintained 38 separate publisher accounts—a strategy that provides resilience against takedowns and makes attribution difficult. By cycling through multiple accounts and brands, the campaign evaded detection longer than a centralized distribution would have permitted.
Key timeline context:
## Technical Details
### Deceptive Privacy Practices
Perhaps most egregious is the contradiction between public claims and actual behavior. Each extension's Chrome Web Store listing explicitly states: "This extension does not collect or use user data." However, Socket researcher Kush Pandya's analysis revealed the extensions actively log:
This harvested information is subsequently shared with major advertising networks including Google AdSense, DoubleClick (Google's programmatic advertising platform), and unnamed third-party ad partners. This represents a clear violation of the extensions' stated privacy policies and user trust.
### Traffic Attribution Fraud
The most sophisticated aspect of this campaign involves fabricated attribution designed to deceive advertising networks. The extensions embed hard-coded URLs and tracking parameters in their js/bg.js JavaScript file, triggered during installation and uninstall:
| Operation | Method | Deception |
|-----------|--------|-----------|
| Installation | Automatic tab opening with UTM parameters | Disguises extension activation as "organic Google search" using utm_source=google&utm_medium=organic |
| Uninstall | Google.com/url redirect wrapper | Mimics genuine Google Search result clicks, complete with signed ved and usg tokens |
In practice, when a user installs one of these extensions, it silently opens a browser tab while stamping the traffic as arriving from an organic Google search—a technique known as organic search simulation. This is not a user who searched Google; it is the extension fabricating the traffic origin.
The uninstall mechanism escalates this deception by wrapping the destination URL in the exact format Google uses for legitimate search-result clicks, including cryptographic tokens (ved and usg parameters). To any external analytics system, the traffic appears identical to a human clicking a genuine Google Search result.
### Dormant Malicious Capabilities
Beyond active data harvesting and fraud, the extensions contain dormant code with additional malicious functionality. Upon service worker initialization, this code can:
IndexedDB is a browser storage mechanism used by many web applications to store user data locally. The ability to delete these databases could destroy:
This capability remains inactive in current samples, suggesting it may be deployed conditionally based on command-and-control signals or reserved for a later campaign phase.
## Implications for Organizations and Users
### For Individual Users
Chrome extension users face several concrete risks from this campaign:
1. Privacy breach: Personal browsing behavior, IP address, and ISP information collected and shared without consent
2. Financial impact: User clicks potentially fraudulently attributed to affiliate programs, inflating advertising costs for legitimate advertisers
3. Data exposure: Harvested information sold or shared with third-party ad networks with weak privacy practices
4. Potential future attacks: Dormant database-deletion capability could be activated remotely
### For Advertising Platforms and Marketers
This campaign represents a sophisticated form of traffic attribution fraud, artificially inflating affiliate commissions and misleading analytics:
The scheme's efficiency—distributing through 38 accounts to reach 105,000 users—suggests significant financial return, making it a highly incentivized fraud vector.
### For Google and the Chrome Ecosystem
The campaign exposes persistent gaps in Chrome Web Store vetting:
## Recommendations
### For Chrome Users
### For Enterprise IT and Security Teams
### For Advertising Networks
---
## HackWire Analysis
This campaign exemplifies a troubling trend: the wholesale industrialization of browser extension fraud. What's significant is not that malicious extensions exist—they do regularly—but the *scale and sophistication* of this particular operation.
The operators demonstrated clear understanding of how advertising attribution works, how Google's URL redirect tokens function, and how to evade Chrome Web Store detection. The decision to fragment across 38 accounts rather than consolidate is not amateur hour; it's a deliberate operational security choice that extends campaign longevity.
More concerning is the dormant database-deletion capability. This suggests the operators are playing a longer game than simple adware distribution. They've established foothold in 105,000 browsers and equipped those footholds with additional attack payloads—potentially to be activated for credential theft, data destruction, or future malware distribution. The fake wallpapers are the Trojan horse; the real threat may come later.
For defenders, this underscores the false dichotomy between "adware" and "advanced threats." Financially motivated threat actors are using the same infrastructure principles as state-sponsored groups: distributed accounts, layered capabilities, dormant payloads. The difference is motivation, not sophistication.
Finally, this campaign indicts both Google's review processes and the advertising industry's verification standards. When extensions can claim "no data collection" while openly harvesting and sharing user data, when traffic can be forged to fool analytics systems, when extensions contain dormant malware for months—the system has failed. Fixes require enforcement, not just policy updates.
— *HackWire Editorial*
---
## Related Coverage