Malicious Extensions Hijack Browser Sessions
Coverage from SecurityWeek, BleepingComputer, and others
Articles
7
Active Days
96
The Topic

Malicious browser extensions are being used as a durable access layer for credential theft, session hijacking, ad fraud, remote code execution, and abuse of authenticated web services. Campaigns affecting Chrome and Edge have used legitimate-looking functionality, delayed or concealed payloads, shared infrastructure, and multiple publisher identities to reach large user populations. The pattern shows that browser add-ons can convert ordinary browsing access into persistent control over identity data, messaging sessions, enterprise credentials, and connected applications.
First Article: 04/14/26
Latest Article: 07/18/26
Summary
- Socket identified more than 100 malicious Chrome extensions across multiple publisher identities, with capabilities including Google OAuth token theft, Telegram session hijacking, arbitrary URL execution, and content injection.
- Microsoft’s StegoAd investigation covered 119 Edge extensions with about 2.6 million installs and at least two years of activity, combining ad and affiliate fraud with credential interception and remote JavaScript execution.
- ACR Stealer campaigns are using ClickFix lures, WebDAV, MSHTA, PowerShell, and in-memory execution to harvest browser passwords, authentication tokens, and sensitive documents from enterprise users.
- Malicious extensions are using delayed activation, steganography, dynamic infrastructure, fingerprinting, and payload variation to evade store review and security scanning.
- A flaw in the Claude for Chrome extension allowed another malicious extension to trigger predefined AI workflows through synthetic clicks, potentially reaching connected services such as Gmail, Google Docs, Calendar, and Salesforce.
- Several campaigns remained available in official extension stores when researchers disclosed them, highlighting the exposure created by trusted distribution channels.
History
The story now emphasizes browser extensions as a broader, more durable access layer for multiple forms of abuse, rather than mainly a credential-theft and session-hijacking threat. It also adds a sharper finding that some malicious extensions were still present in official stores when disclosed, underscoring the persistence of trusted-channel abuse.
The story expands beyond store-distributed browser-extension malware to include a new delivery chain, ACR Stealer, and a separate Claude for Chrome flaw that lets extensions trigger authenticated AI workflows. It also sharpens the scale and technical sophistication of the extension campaigns, especially StegoAd’s install base and concealed execution methods.
