Automatically translated.View original post

Data theft malware found on 108 other Chrome add-ons

Data theft malware was detected on 108 other Chrome add-ons, hitting over 20,000 victims.

Web browser add-ons or extensions can help web browsers to perform a variety of tasks, creating ease for users, but many fake malware add-ons have now been detected that can cause users, rather than ease, to suffer.

According to a report by the website, The Hacker News has mentioned the detection of up to 108 fake Chrome web browser add-ons that all behave in the same way: they are connected to the same C2 or Command and Control command infrastructure. They will contact the C2 server located at 144.126.135. [.] 238. These add-ons have the same purpose: they are used to steal Credential, User Identity, and Website Visiting Information. Even worse, 56 of the 108 add-ons are capable of stealing Google accounts through OAuth2, 45 of them have the ability to be a backdoor for hackers to use in the following activities:

Exfiltration of Telegram chat application every 15 seconds

Remove critical headers of WFP and Youtube such as Content Security Policy, X-Frame-Options, and CORS and shoot the Injection code to display online gambling website ads instead.

Shoot the script to display the content required by the hackers on every website the victim accesses.

Redirect (Proxy) Translation Request to Hacker's Server

According to a research team from Socket, a cybersecurity specialist, the 108 add-ons come from just five publishers including Yana Project, GameGen, SideGames, Rodeo Games and InterAlt. With a total of over 20,000 add-ons installed today, examples of dangerous add-ons are as follows:

Telegram Multi-Account (ID: obifanppcpchlehkjipahhphbcbjekfa) An add-on that claims to enable multiple Telegram accounts at the same time, but actually secretly steals the user _ auth's Token, which is used to authenticate users' identities on the Telegram Web, sent back to hackers, as well as can overwrite localStorage with Session data. Use sent by hackers to turn the victim's Session into the Session required by hackers instead.

Web Client for Telegram - Teleside (ID: mdcfennpfgkngnibjbpnpaafcjnhcjno) has the ability to remove Telegram's Header and then shoot the script for stealing the victim's account.

Formula Rush Racing Game (ID: akebbllmckjphjiojeioooidhnddnplj) is used to steal Google accounts through tricking them into pressing the Sign-In button. The stolen data consists of emails, profile photos, full names, and Google account numbers.

The source does not indicate whether Google has removed these dangerous add-ons from the Web Store or not yet. It is not yet possible to determine who is behind this outrageous incident, but there is an assumption that hackers from Russia may be behind it because of the large number of Russian language inserts in the add-ons' code.

# Trending # Lemon 8 Howtoo # lemon 8 diary # chrome # freedomhack

3 days agoEdited to

... Read moreจากประสบการณ์ผมในการใช้งานเว็บเบราว์เซอร์ Chrome มา ผมมักจะติดตั้งส่วนเสริม (Extension) ที่ช่วยอำนวยความสะดวกต่าง ๆ เช่น บล็อกโฆษณา หรือช่วยจัดการรหัสผ่าน แต่ข่าวการเจอมัลแวร์แฝงในส่วนเสริมถึง 108 ตัวนี้ทำให้ผมต้องทบทวนและปรับพฤติกรรมทันที สิ่งที่สำคัญคือ ต้องเลือกติดตั้งส่วนเสริมจากแหล่งที่น่าเชื่อถือเท่านั้น เช่น ผู้พัฒนาที่มีชื่อเสียงและรีวิวดี ๆ ไม่ควรติดตั้งส่วนเสริมที่ไม่มีข้อมูล หรือคะแนนรีวิวน้อย เพราะมัลแวร์เหล่านี้จะทำงานผ่านการเชื่อมต่อกับเซิร์ฟเวอร์ Command and Control (C2) ซึ่งมีเป้าหมายในการขโมยข้อมูลส่วนตัว เช่น รหัสผ่าน บัญชี Google ผ่านระบบ OAuth2 ไปจนถึงการลบบางส่วนหัวของเว็บไซต์ยอดนิยมอย่าง TikTok และ Youtube เพื่อฉีดโฆษณาเว็บไซต์การพนันเข้ามาแทน อยากแนะนำให้ผู้ใช้ Chrome ตรวจสอบสิทธิ์ของส่วนเสริมอย่างสม่ำเสมอโดยเข้าที่เมนูจัดการส่วนเสริม แล้วดูสิทธิ์ที่ขอใช้งานว่ามากเกินควรหรือไม่ และถ้าไม่แน่ใจอย่ากดอนุญาต นอกจากนี้ การติดตั้งโปรแกรมแอนตี้มัลแวร์ และเปิดใช้งานการอัปเดตเบราว์เซอร์กับส่วนเสริมเป็นเวอร์ชันล่าสุดเสมอ จะช่วยลดความเสี่ยง สำหรับใครที่ใช้ Telegram ผ่านเว็บแล้วมีส่วนเสริมที่บอกว่าสามารถจัดการหลายบัญชีได้ ควรระวังเป็นพิเศษ เพราะมัลแวร์กลุ่มนี้ใช้วิธีขโมย token ยืนยันตัวตน ส่งกลับไปให้แฮกเกอร์พร้อมกับปรับเปลี่ยน session ของผู้ใช้งานได้ด้วย ท้ายที่สุด การรับรู้และเรียนรู้เกี่ยวกับภัยคุกคามเหล่านี้ รวมถึงเตรียมรับมือด้วยการตั้งค่าความปลอดภัยที่เหมาะสม จะช่วยปกป้องข้อมูลส่วนตัวของเราไม่ให้รั่วไหลไปสู่มือผู้ไม่หวังดี ส่วนนี้เป็นบทเรียนให้เราต้องไม่ประมาทในการใช้เทคโนโลยีดิจิทัลในปัจจุบัน

Related posts

It's no secret that Karol G just slayed the #Grammys #Glambot . #AwardsSeason
user6854050772614

user6854050772614

11 likes

Why I switched to taking notes on my iPad
I used to love writing in notebooks, but after switching to my iPad, I can confidently say I’m never going back! Here’s why: ✨ Cuter Notes – Let’s be real…aesthetic notes make studying more enjoyable! I can use custom colors, cute stickers, and different handwriting styles to make my notes visua
Rebecca R.

Rebecca R.

263 likes

A young woman with long dark hair, wearing a pink satin shirt, smiles at the camera while sitting at a table. Overlay text reads: 'Tools and sites I use as a cybersecurity student to progress my skills and keep me interested in studying'.
A screenshot of 'The Hacker News' website, displaying various cybersecurity news articles from January 2025, including topics like vulnerabilities, malware, cyber espionage, and AI jailbreak methods. An ad for Zscaler and a banner for CIS Hardened Images are also visible.
A screenshot of the O'Reilly learning platform, showing various books and expert playlists related to AI, engineering, and data. Overlay text highlights the subscription cost ($50/month or $499/year) and its value for accessing books and live events.
Tools and sites I use as a cybersecurity student 🌸
#cybersecuritystudent #cybersecurity #techgirlie
LexiStudies

LexiStudies

105 likes

APK GTA
roblox

roblox

67 likes

Build This Alternate Famous Cartoon Car In GTA
JayWayyGaming

JayWayyGaming

6 likes

SOS!!! Wha do you do if you click a phishing email link… two times?!? So far I have: 1, added two factor sign on 2, changed my passwords 3, stress cried and spiraled But for real. What do you do… how do I know if there is now malware (? Is that what it’s called ?) living on my computer?!?
Alexandra Wildeson

Alexandra Wildeson

2 likes

Developing a career in cybersecurity
Hey All! 👋 Want to stay safe online and protect your data? Cybersecurity knowledge is essential. It helps you secure your personal information and understand how to safeguard your digital footprint. Let’s dive into why it’s crucial! 💻🔒 Why Cybersecurity Matters Cybersecurity is about protecting
Meghana

Meghana

550 likes

Build This Famous TV Car From The 80’s
JayWayyGaming

JayWayyGaming

8 likes

Elite Hacker Destroyed His Empire By Forgetting On
Bro, I really forgot to use a VPN 💀 #hacker #cybercrime #fail #tech #arrestedstupidly
arrestedstupidly

arrestedstupidly

1 like

roblox

roblox

1 like

SATURDAY | 2 MAY 2026 | Cybersecurity Report
The digital frontlines just got a lot more dangerous. Today on Cyber F.M., host Arias Thomas breaks down the industrialization of cybercrime and the collapse of the software supply chain. If you think your "secure" tools are safe, think again. Inside Today’s Broadcast: 🏮 The Paperclip
Cyber F.M.

Cyber F.M.

3 likes

Build This Famous 70’s TV Show Car In GTA
JayWayyGaming

JayWayyGaming

5 likes

JayWayyGaming

JayWayyGaming

26 likes

How to Make a Dyson Sphere in Sandboxels
#dysonsphere #science #sciencegames #gaming #pixelart
R74n

R74n

7 likes

Files Copied to USB Drive Disappear? Lets Recover
Copied files to your USB drive, then they vanished? This issue is often caused by hidden files, unsafe ejection, corruption, or failing flash storage. This guide shows how to reveal hidden files, repair USB errors, and recover missing data safely before it gets overwritten. #usb #datarecovery
XanthusTechCore

XanthusTechCore

3 likes

Front view of a gray 2019 INFINITI Q50 3.0T LUXE sedan, showcasing its grille, headlights, and Infiniti logo. A 'BEST VALUE' sticker is on the windshield, with other cars and a dealership in the background.
Rear quarter view of a gray 2019 INFINITI Q50 3.0T LUXE, highlighting the lip rear spoiler, dual blue-tipped exhaust, and black alloy wheels. The car is parked on asphalt.
Front quarter view of a gray 2019 INFINITI Q50 3.0T LUXE, showing its sleek design, headlights, and black alloy wheels. The car is parked outdoors under a sunny sky.
2019 INFINITI Q50 3.0T LUXE Price:$4,300 Down payment:$500 Comfort interior Miles: 105,939k Accident Avoidance Systems Adjustable Lumbar Support Alloy Wheels Anti-Theft System Approach Lights Auto-dimming Rearview Mirror Automatic Climate Control Bluetooth Braking Assist Bucket
Classic_Cars_For_Sale

Classic_Cars_For_Sale

1 like

Check out this website that helps you when you’re feeling uninspired! I walk you thru the process of downloading the svg file to taking it to cricut design space! Happy crafting. #designinspo #creativeart #cricutprojects #svgfiles #CricutTips
VlunaWorks

VlunaWorks

46 likes

+it’s less than 80$✨❗️LINK for this item in my bio❗️
Details⬇️: This flip phone smartphone with a flip keyboard design, offering both the convenience of a traditional keypad and the functionality of a modern touchscreen device. With 4GB of internal storage, you'll have plenty of space for apps, photos, and more. The compact 3.5" displa
Atlas

Atlas

443 likes

#evakuasi #sidoajo #fyp
abesso

abesso

1 like

Free SVG files for Cricut Design Space. If you’re dealing with crafter’s block, this website has tons of free SVG downloads to spark new project ideas for shirts, stickers, bookmarks, and more. Save this for your next Cricut project and start creating again 💕 #designinspo #creativeart
VlunaWorks

VlunaWorks

5 likes

✨ Stand out during the holidays with this combo!
Tonight's combo is one that will make you stand out. Key notes: Honey, vanilla, amber. With a light hint of tobacco. 💌 Brand: @TheTipsyGoatSoapCompany Honey Toffee 💌 Brand: @Jebouri | Arabian Perfumery honey amber 💌 Brand: @Guerlain Tobacco Honey #عطر #عطور #perfumetiktok #
✨it's malware✨

✨it's malware✨

1 like

A cozy, white-themed desk setup with a monitor displaying a customized Chrome browser, surrounded by white accessories and plushies, with a search bar overlay 'how to customize your chrome browser'.
A computer screen showing the Google Chrome Web Store search results, with an overlay instructing '1. Go to the chrome web store :)'. A digital clock shows '03:39' below.
A computer screen displaying the Chrome Web Store's 'Themes' section, with an arrow pointing to the 'Themes' tab and text '2. Click the "themes" in the top left'.
Chrome but make it cozy 🤍✨️
Hey everyone! Most people probably know about this, but I wanted to share for those who don’t — customizing your Chrome browser is actually really fun! You can change up the look, add a pop of color, or match it to your vibe with just a few clicks. It’s a small change, but it makes your browsing fe
˚ʚ N e o n ɞ˚

˚ʚ N e o n ɞ˚

243 likes

Build This Famous Movie MUSCLE Car
JayWayyGaming

JayWayyGaming

8 likes

A shelf filled with books, two paintings, and various decorative items, with text overlay stating "Day in the life Of a college student -day of no classes -late start to the day."
A neatly made bed with floral bedding, a white headboard, and a stuffed animal, alongside a white dresser, with text overlay "Woke up: 9:30am, made my bed."
A MacBook Air laptop open on a bed, displaying a YouTube video titled "25 Minute DUMBBELL Arms & Abs EMOM Workout," with text overlay "Did an upper-body workout!"
Day in the life of a messy college student 🫶🍵
#college #dayinmylife
Daniella Uriev

Daniella Uriev

8 likes

You need TikTok ?
Here is how you can download TikTok if you need help with and apple phone just ask me I can help with Apple phone you need to change your region on the Apple Pay store
Ali

Ali

10 likes

gta5
#legendmobile #embracevulnerability #summerbod #embracevulnerability #summerbod
roblox

roblox

1 like

Never plug your phone or computer into usb plugs in hotels or airports here’s why 👇🏼 A USB port doesn’t just deliver power, it can also transfer data. A compromised hotel USB outlet could secretly install malware on your phone or copy your data without you realizing it. Hotels, airports, and o
Cybersecurity Girl

Cybersecurity Girl

150 likes

JayWayyGaming

JayWayyGaming

1 like

watch the whole video like share and follow me
#fypシ
John Damico

John Damico

1 like

Back Up Outlook Emails to an External Hard Drive
Need to back up your Outlook emails to an external hard drive? Here are 2 simple methods to help you out. Download AOMEI Backupper and give it a try! #backup #outlook #externalharddrive
SmoothTechie

SmoothTechie

1 like

⚡ How to Make Your PC Run Faster – 5 Easy Tips! 🖥️🔥
💡 1. Disable Startup Programs 🚀 Too many apps launching at startup slow down your PC! ✅ Open Task Manager (Ctrl + Shift + Esc) ✅ Go to the Startup tab ✅ Disable unnecessary apps to speed up boot time 💡 2. Clean Temporary Files 🗑️ Over time, junk files slow your system down. ✅ Press Win
skaeszun

skaeszun

284 likes

Supply Chain Attack on 30+ WordPress Plugins
Supply Chain Attack on 30+ WordPress Plugins | Wordfence Security News Clip | April 13, 2026 A buyer acquired more than 30 WordPress plugins through the Flippa marketplace after purchasing the Essential Plugin portfolio for a six-figure sum, then planted a backdoor in every plugin as their very
Wordfence

Wordfence

1 like

How to Install Windows on a Second Hard Drive
Learn how to use AOMEI Cloner to clone your existing system to another drive. This makes it easy to back up and restore data in the event of a system crash or malware attack. Download it today and give it a try! #harddrive #clone #hdd #ssd #windows
RedFFTech

RedFFTech

0 likes

📍USB Write Protected? Fix It Instantly
Seeing “The disk is write-protected” error on your USB drive? This quick guide shows how to remove write protection and regain full access to your files. Learn how to check the physical lock switch, use DiskPart commands, repair file system errors, and fix registry issues step by step. Many cases a
XanthusTechCore

XanthusTechCore

5 likes

Recover Hidden Files from USB Using Command Prompt
Can’t see your files on a USB stick even though they’re there? This video shows how to use Command Prompt commands (like attrib) to unhide files hidden by system attributes or viruses — plus what to try if that doesn’t work. #USB #cmdanks #windows 11 #techtutorial #newonlemon8
XanthusTechCore

XanthusTechCore

2 likes

🚨 16 Billion passwords leaked - the largest breach ever 🚨 Here is how it happened and what you can do to be safe. #news #databreach #cybersecuritytips #onlinesafety
Cybersecurity Girl

Cybersecurity Girl

123 likes

Squid Game Cookies in Sandboxels
#game #gaming #baking #squidgame #dalgona #games
R74n

R74n

87 likes

virus
👍Pros :
F3X

F3X

1 like

😫 Wanting to quit your 9-5?
Becoming a Pinterest Manager might be for you! In less than a year, I went from earning $2K at my 9-5 to over $4K/month with Pinterest management alone. Now, with all the different skills and platforms I lesrned, I make anywhere from $12-15K A MONTH! Back then, I knew I had to do something
Bria | Social, Design, & AI

Bria | Social, Design, & AI

482 likes

Oscar Esparza Hacker

Oscar Esparza Hacker

0 likes

productivity apps on your mac!
Proton VPN for staying secure online and Grammarly for making sure I don’t send embarrassing emails literally two apps I use daily to stay productive without the stress. If you’re not using them yet, you’re missing out! #lemon8partner #lemon8creator #tech #apps #productivity
asmae🐸

asmae🐸

19 likes

Google probably installed an AI on your computer. Let’s get rid of it together #fyp
PiratePrincessJess

PiratePrincessJess

0 likes

See more