100+ Fake Chrome Extensions Found Hijacking Sessions, Stealing Credentials,
Injecting Ads
thehackernews.com/2025/05/1…
An unknown threat actor has been attributed to creating several malicious
Chrome Browser extensions since February 2024 that masquerade as seemingly
benign utilities but incorporate covert functionality to exfiltrate data,
receive commands, and execute arbitrary code.
“The actor creates websites that masquerade as legitimate services,
productivity tools, ad and media creation or analysis assistants, VPN
services, crypto, banking and more to direct users to install corresponding
malicious extensions on Google’s Chrome Web Store (CWS),” the DomainTools
Intelligence (DTI) team said in a report shared with The Hacker News.
While the browser add-ons appear to offer the advertised features, they also
enable credential and cookie theft, session hijacking, ad injection, malicious
redirects, traffic manipulation, and phishing via DOM manipulation.
Another factor that works in the extensions' favor is that they are configured
to grant themselves excessive permissions via the manifest.json file,
allowing them to interact with every site visited on the browser, execute
arbitrary code retrieved from an attacker-controlled domain, perform malicious
redirects, and even inject ads.