Last Update: 08/01/2026 at 1:00 PM EST

Malicious Extensions Hijack Browser Sessions

Coverage from SecurityWeek, BleepingComputer, and others

Articles

7

Active Days

96

The Topic

Malicious Extensions Hijack Browser Sessions topic image

Malicious browser extensions are being used as a durable access layer for credential theft, session hijacking, ad fraud, remote code execution, and abuse of authenticated web services. Campaigns affecting Chrome and Edge have used legitimate-looking functionality, delayed or concealed payloads, shared infrastructure, and multiple publisher identities to reach large user populations. The pattern shows that browser add-ons can convert ordinary browsing access into persistent control over identity data, messaging sessions, enterprise credentials, and connected applications.

First Article: 04/14/26

Latest Article: 07/18/26

Summary

  • Socket identified more than 100 malicious Chrome extensions across multiple publisher identities, with capabilities including Google OAuth token theft, Telegram session hijacking, arbitrary URL execution, and content injection.
  • Microsoft’s StegoAd investigation covered 119 Edge extensions with about 2.6 million installs and at least two years of activity, combining ad and affiliate fraud with credential interception and remote JavaScript execution.
  • ACR Stealer campaigns are using ClickFix lures, WebDAV, MSHTA, PowerShell, and in-memory execution to harvest browser passwords, authentication tokens, and sensitive documents from enterprise users.
  • Malicious extensions are using delayed activation, steganography, dynamic infrastructure, fingerprinting, and payload variation to evade store review and security scanning.
  • A flaw in the Claude for Chrome extension allowed another malicious extension to trigger predefined AI workflows through synthetic clicks, potentially reaching connected services such as Gmail, Google Docs, Calendar, and Salesforce.
  • Several campaigns remained available in official extension stores when researchers disclosed them, highlighting the exposure created by trusted distribution channels.

History

07/23/2026

The story now emphasizes browser extensions as a broader, more durable access layer for multiple forms of abuse, rather than mainly a credential-theft and session-hijacking threat. It also adds a sharper finding that some malicious extensions were still present in official stores when disclosed, underscoring the persistence of trusted-channel abuse.

07/21/2026

The story expands beyond store-distributed browser-extension malware to include a new delivery chain, ACR Stealer, and a separate Claude for Chrome flaw that lets extensions trigger authenticated AI workflows. It also sharpens the scale and technical sophistication of the extension campaigns, especially StegoAd’s install base and concealed execution methods.

Featured

Timeline: 96 Days

Apr 14May 5May 19Jun 9Jun 23Jul 14

Additional Articles

⭐⭐⭐⭐⭐

BleepingComputer / Bill Toulas04-14-2026
Socket researchers reported a coordinated Chrome Web Store extension campaign that used command and control infrastructure to hijack sessions and steal Google OAuth tokens.
Security Affairs / Pierluigi Paganini06-29-2026
Microsoft disrupted the StegoAd campaign in Microsoft Edge extensions after the campaign stole Google sign-in passwords and two-factor codes for at least two years.
Security Affairs / Pierluigi Paganini06-29-2026
Microsoft documented the StegoAd Edge extension campaign, active since 2021, using steganography and delayed execution to perform ad fraud and credential theft.
Let's Data Science06-30-2026
MalExt Sentry researchers disclosed a June 13, 2026 campaign where two browser extensions allegedly recorded and transmitted AI prompts and responses using a hidden consent option.