Hundreds of Chrome extensions harvest Google tokens and Telegram sessions

1 min read
Source: BleepingComputer
Hundreds of Chrome extensions harvest Google tokens and Telegram sessions
Photo: BleepingComputer
TL;DR

Security researchers found over 100 malicious Chrome Web Store extensions from five publishers that steal Google OAuth2 Bearer tokens, harvest account data, hijack Telegram Web sessions, and run backdoors via a centralized C2; the campaign, likely a Russian MaaS operation, remains active in the store, and Google has been notified—users should uninstall any matching extensions.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer