Skip to main content
  1. Home
  2. Computing
  3. News

Over a hundred Chrome extensions discovered raising hell. Check out if you’ve been using one

Some looked harmless, but a new report says they siphoned identity data and opened attack paths

Add as a preferred source on Google
malicious-google-chrome-extensions-on-web-store
Chris DeGraw / Digital Trends

More than 100 Chrome extensions have been tied to a sprawling campaign that harvested identity data, opened backdoor-style browser behavior, and in one case pulled live Telegram Web session data. Researchers linked 108 add-ons to the same control network, with about 20,000 installs logged across the Chrome Web Store when the findings were published.

What makes this one hit harder is the range. The extensions showed up as Telegram tools, slot and Keno games, translation utilities, YouTube and TikTok helpers, and basic page tools, which helped the operation blend into the kind of stuff people install without much thought. See the full list here.

Recommended Videos

Researchers said the extensions were still live when the report went up, and takedown requests had already been filed. That gives this story a very practical edge for Chrome users who haven’t checked their add-ons in a while.

The worst behavior wasn’t all the same

The damage wasn’t limited to one trick. The research found that 54 extensions collected Google account identity details after a user clicked a sign-in button, while one Telegram-focused extension exfiltrated active Telegram Web session data every 15 seconds. Another 45 included a routine that could open arbitrary URLs whenever Chrome started, even if the user never opened the extension that day.

Other add-ons stripped security protections from sites like Telegram, YouTube, and TikTok before injecting overlays, ads, or scripts into pages. One translation tool also routed submitted text through the operator’s server, turning a simple helper into a surveillance risk.

Why this should worry regular Chrome users

The bigger issue is how ordinary the bait looked. These weren’t just obscure tools for power users. The list included games, browser helpers, sidebar clients, and translation add-ons, exactly the kind of extras people grab because the store page looks polished and the feature seems useful.

Extensions also tend to fade into the background once they’re installed. In this case, researchers traced activity from that mixed bag of tools back to the same backend infrastructure, which turned a random-looking pile of add-ons into one operation with several ways to collect data or alter the browsing experience.

Check your extensions now

The smartest next move is to audit what’s installed in Chrome, especially anything tied to Telegram, lightweight games, translation, or sidebar utilities that asked for sign-in access without a clear reason. The research lists 108 extensions by name and ID, and recommends removing any match immediately.

The highest-risk case appears to be the Telegram extension that repeatedly exfiltrated web session data. Anyone who used it while logged into Telegram Web should terminate other Telegram sessions from the mobile app, and users who signed into one of the Google-linked extensions should review account access and revoke anything unfamiliar.

Paulo Vargas
Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
Copilot could soon help diagnose issues with your PC
A new PC Insights feature will help you find what's slowing down your PC, though Copilot itself may be one of the main problems.
Microsoft Copilot Banner Featured

Copilot's next trick is diagnosing your PC's problems, but the catch is that the assistant doing the diagnosing is itself part of the problem. Windows Latest reports that Microsoft is testing a new Copilot feature called PC Insights, which will let you ask the AI assistant natural language questions about your computer's hardware and storage instead of digging through the Task Manager or Settings. The feature will reportedly allow users to ask questions like, "Do I have enough space for a 100GB game?" and Copilot will check the available storage to offer a response. Users will also be able to ask about CPU usage, battery health, etc., to diagnose issues.

What Copilot will be able to see

Read more
OpenAI just took the handcuffs off your ChatGPT Work and Codex usage limits, at least for now
The 5 hour limit is gone for now, your usage counter just reset, and GPT 5.6 Sol is about to get a lot lighter on your allowance.
OpenAI logo on Microsoft surface

It seems that OpenAI has been on a gallop lately, releasing new updates left and right. Just a few days back, the company launched its GPT-5.6 Sol, Terra, and Luna models for the general public, and now it's back with another update that will please its users even more. 

The headline change is that the 5-hour usage limit restriction in ChatGPT Work and Codex is being temporarily removed for all Plus, Business, and Pro plans. If you have ever been in the middle of a long working session and watched the limit message appear at the worst possible moment, this one is for you. 

Read more
This app gives your Mac a music player you’ll actually enjoy using
Apple Music on the Mac is a chore. Liqoria is the fix, and it plays nice with Spotify and YouTube too.
Liqoria music player

The Apple Music app on the Mac is not up to the mark. I don’t like how it looks or behaves, and Apple should take some inspiration from Spotify to make the app more modern and useful. Until that happens, we are stuck with a subpar app experience.

That’s why I never use the Apple Music app on my Mac and rely on third-party apps that let me control music. Today I am featuring one of the latest apps I discovered. It’s called Liqoria, and it’s probably the only music player app you will ever need.

Read more