108 Malicious Chrome Extensions Share C2 Infrastructure for Session Cookie Theft and Browser Data Exfiltration — Threadlinqs Intelligence
As of 2026-05-30, 108 Malicious Chrome Extensions Share C2 Infrastructure for Session Cookie Theft and Browser Data Exfiltration is a high-severity malware threat attributed to Ext-Cluster-108 (N/A), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0358 · Severity: HIGH · CVSS: 8.1 · Status: ACTIVE · Category: MALWARE
Attribution: Ext-Cluster-108 · N/A · FINANCIAL
Socket Security disclosed a cluster of 108 malicious Chrome extensions distributed through the Chrome Web Store that share common command-and-control infrastructure for stealing authenticated session
On April 12, 2026, Socket Security's threat research team disclosed a coordinated malware campaign involving 108 malicious Chrome extensions published to the Chrome Web Store under multiple developer accounts. All 108 extensions were found to share a common command-and-control infrastructure, including overlapping reporting endpoints (api-sync[.]xyz, cdn-metrics[.]co, telemetry-hub[.]net) and identical payload staging domains, strongly suggesting a single threat actor or tightly coordinated cluster operated the campaign.
The extensions impersonated legitimate productivity, VPN, cryptocurrency wallet, and AI assistant tools, leveraging the reach and implied trust of the Chrome Web Store to trick users into installing them. Upon installation, each extension requested broad permissions (<all_urls>, cookies, storage, tabs, webRequest) and used the chrome.cookies API to harvest authenticated session cookies from high-value targets such as Google Workspace, Microsoft 365, Facebook, LinkedIn, GitHub, Coinbase, Binance, and online banking portals. Stolen cookies were exfiltrated via HTTPS POST to C2 endpoints and enabled downstream account takeover, business email compromise, and cryptocurrency theft without requiring passwords or bypassing multi-factor authentication.
Several extensions also injected remote third-party JavaScript into visited pages via chrome.scripting.executeScript, supporting credential harvesting, form-grabbing, and ad-injection monetization. A subset of extensions performed DOM-based screen scraping to collect page content, including banking balances, messaging threads, and CRM records. The extensions used obfuscated JavaScript bundles (packed with Terser and rot13 string rotation) and dynamic code evaluation via Function constructors and dynamic import() to bypass Chrome Web Store automated review.
Socket attributes the campaign's persistence to compromised and newly registered developer accounts, aged domains, and rapid cycling of extension IDs after takedown. Google has begun removing the identified extensions, but users who installed them remain at risk of credential and session-token compromise until passwords are rotated and active sessions invalidated across affected services. The campaign aligns with a broader trend of browser-extension-based initial access, session hijacking, and supply-chain-style compromise of end-user browsers that has dominated 2025-2026 threat telemetry.
Weaknesses (CWE)
CWE-829, CWE-494, CWE-506, CWE-749, CWE-200
Target sectors: technology, financial, cryptocurrency, government, healthcare, education, media, retail
Target regions: North America, Europe, Asia-Pacific, Latin America, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1195, T1189, T1204, T1059, T1176, T1027, T1036, T1140, T1539, T1555