Skip to main content
  1. Home
  2. Computing
  3. News

Over a hundred Chrome extensions discovered raising hell. Check out if you’ve been using one

Some looked harmless, but a new report says they siphoned identity data and opened attack paths

Add as a preferred source on Google
malicious-google-chrome-extensions-on-web-store
Chris DeGraw / Digital Trends

More than 100 Chrome extensions have been tied to a sprawling campaign that harvested identity data, opened backdoor-style browser behavior, and in one case pulled live Telegram Web session data. Researchers linked 108 add-ons to the same control network, with about 20,000 installs logged across the Chrome Web Store when the findings were published.

What makes this one hit harder is the range. The extensions showed up as Telegram tools, slot and Keno games, translation utilities, YouTube and TikTok helpers, and basic page tools, which helped the operation blend into the kind of stuff people install without much thought. See the full list here.

Recommended Videos

Researchers said the extensions were still live when the report went up, and takedown requests had already been filed. That gives this story a very practical edge for Chrome users who haven’t checked their add-ons in a while.

The worst behavior wasn’t all the same

The damage wasn’t limited to one trick. The research found that 54 extensions collected Google account identity details after a user clicked a sign-in button, while one Telegram-focused extension exfiltrated active Telegram Web session data every 15 seconds. Another 45 included a routine that could open arbitrary URLs whenever Chrome started, even if the user never opened the extension that day.

Other add-ons stripped security protections from sites like Telegram, YouTube, and TikTok before injecting overlays, ads, or scripts into pages. One translation tool also routed submitted text through the operator’s server, turning a simple helper into a surveillance risk.

Why this should worry regular Chrome users

The bigger issue is how ordinary the bait looked. These weren’t just obscure tools for power users. The list included games, browser helpers, sidebar clients, and translation add-ons, exactly the kind of extras people grab because the store page looks polished and the feature seems useful.

Extensions also tend to fade into the background once they’re installed. In this case, researchers traced activity from that mixed bag of tools back to the same backend infrastructure, which turned a random-looking pile of add-ons into one operation with several ways to collect data or alter the browsing experience.

Check your extensions now

The smartest next move is to audit what’s installed in Chrome, especially anything tied to Telegram, lightweight games, translation, or sidebar utilities that asked for sign-in access without a clear reason. The research lists 108 extensions by name and ID, and recommends removing any match immediately.

The highest-risk case appears to be the Telegram extension that repeatedly exfiltrated web session data. Anyone who used it while logged into Telegram Web should terminate other Telegram sessions from the mobile app, and users who signed into one of the Google-linked extensions should review account access and revoke anything unfamiliar.

Paulo Vargas
Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
Huawei made its giant folding laptop faster and tougher, but the pen is the real upgrade
Huawei’s giant folding laptop is back tougher, faster, and pen-ready
Huawei MateBook Fold Ultimate Design being used with the M3-Pen

Huawei’s laptop that opens into an 18-inch OLED screen already looked pretty futuristic when it first debuted. But the 2026 update makes the laptop even better. The company has improved performance and display durability, which brings another layer of interaction.

The refreshed Huawei MateBook Fold Ultimate Design unfolds into an 18-inch, 3296 x 2472 dual-layer OLED display with a 4:3 aspect ratio, 1,600 nits of peak brightness, and a 92% screen-to-body ratio. Fold it into a laptop shape, and each half becomes a more portable 13-inch, 3:2 screen. Despite that enormous panel, the device weighs 1.16kg without its detachable keyboard. It measures 7.3mm at its thinnest point when open and 14.9mm when closed.

Read more
Study finds readers rate AI-written stories higher, but still trust the “human” label more
Researchers also found that readers could barely differentiate between AI-generated and human-written stories, though those familiar with AI tools guessed somewhat better.
updated book and AI photo

If you think AI writing is easy to spot, a new study suggests you may be overestimating your ability to tell the difference. Researchers from Villanova University have found that readers struggled to tell AI-generated stories from human-written ones and frequently rated the AI versions higher.

The study, led by Dr. Deena Skolnick Weisberg and published in the journal Judgment and Decision Making (via The Guardian), asked more than 1,600 participants to rate one of six short stories, three written by a human and the rest generated by ChatGPT, on quality and engagement. Participants were told who wrote their story, though that label wasn't always accurate.

Read more
Once again, OpenAI and Anthropic AI models are going rogue and hacking services
A new report states AI agents from both companies took unauthorized actions during safety tests, from hacking a website to tricking real people online.
Claude website open on laptop

OpenAI and Anthropic have both had a rough few weeks on the AI safety front. OpenAI recently disclosed that its models broke out of a test environment and hacked into Hugging Face and four other organizations. The news prompted Anthropic to review its own testing, which revealed that Claude had also gained unauthorized access to three companies.

Now, the UK's AI Security Institute (AISI) has disclosed a new round of incidents (via Wired). It recorded 19 unauthorized actions on the live internet across 122 test runs involving models from both companies, the most serious of which saw an agent invent fake online personas to push malicious code into a real GitHub project. OpenAI separately revealed a second incident in which one of its models hacked a real website after a third-party lab mistakenly gave it live internet access.

Read more