Hundreds of Chrome extensions harvest Google tokens and Telegram sessions

TL;DR
Security researchers found over 100 malicious Chrome Web Store extensions from five publishers that steal Google OAuth2 Bearer tokens, harvest account data, hijack Telegram Web sessions, and run backdoors via a centralized C2; the campaign, likely a Russian MaaS operation, remains active in the store, and Google has been notified—users should uninstall any matching extensions.
- Over 100 Chrome Web Store extensions steal user accounts, data BleepingComputer
- 108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users The Hacker News
- 108 malicious Chrome extensions found stealing data and injecting ads into every page you visit — delete them right now Tom's Guide
- Google Attack Warning—Chrome Hackers Target Gmail And YouTube Users Forbes
- These 4 Chrome extensions started clean, then turned into malware How-To Geek
Want the full story? Read the original reporting
Read on BleepingComputer