Threat reportSupply ChainTL-2026-0363
108 Malicious Chrome Extensions Steal OAuth Tokens, Hijack Telegram Sessions, and Deploy Backdoors via Shared C2 Infrastructure
108 Malicious Chrome Extensions Steal OAuth Tokens, Hijack (TL-2026-0363), also tracked as Chrome Web Store MaaS Campaign, is a high-severity supply-chain compromise scored CVSS 8.1, first published 2026-04-14. It carries a reported Russia nexus and is not formally attributed, affects Google Chrome Browser, maps to 20 MITRE ATT&CK techniques (T1027, T1036, T1041), and is covered by 9 detection rules and 35 indicators of compromise.
- CVSS
- 8.1/10High
- CVEs
- 0None referenced
- Techniques
- 20MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 35Indicators of compromise
Key facts for TL-2026-0363
- Threat ID
- TL-2026-0363
- Also known as
- Chrome Web Store MaaS Campaign, CloudAPI.stream Campaign
- Severity
- HIGH
- CVSS
- 8.1
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- NONE
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- technology, enterprise, consumer, financial, government, education
- Target regions
- Global, North America, Europe, Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 35
How 108 Malicious Chrome Extensions Steal OAuth Tokens, Hijack works
Socket researchers identified 108 malicious Chrome extensions published under five fake publisher identities in the Chrome Web Store, collectively amassing ~20,000 installs. The extensions steal Google OAuth2 bearer tokens, exfiltrate Telegram Web sessions every 15 seconds enabling full account takeover, deploy universal backdoors that open arbitrary URLs on browser startup, inject gambling overlays via DOM XSS, and strip security headers from YouTube, TikTok, and Telegram. All extensions share a single C2 server at 144.126.135.238 (Contabo GmbH) using the cloudapi.stream domain with 14+ specialized subdomains.
A coordinated supply chain campaign discovered by Socket's Threat Research Team (researcher Kush Pandya) has identified 108 malicious Chrome extensions operating under a unified command-and-control infrastructure. The extensions are published under five distinct Chrome Web Store publisher identities — Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt — masquerading as Telegram sidebar clients, slot machine and casino games, YouTube/TikTok enhancers, a text translation tool, and browser utilities. Despite the apparent diversity, all 56 unique OAuth2 client IDs across the campaign trace to only two Google Cloud projects (1096126762051 and 170835003632), proving single-operator control.
The campaign employs seven distinct malicious capabilities across overlapping extension subsets:
1. Google OAuth2 Identity Harvesting (54 extensions): Upon user interaction, extensions acquire a real Google OAuth2 Bearer token via chrome.identity.getAuthToken({interactive: true}), then fetch the victim's full profile (email, name, picture, persistent Google account sub identifier) from googleapis.com/oauth2/v3/userinfo and exfiltrate it to mines.cloudapi.stream/auth_google. This creates a persistent reconnaissance database of victim identities linked to extension-specific user IDs.
2. Universal Backdoor via loadInfo() (45 extensions): A hidden function executes automatically on every browser startup before the service worker initializes. It POSTs the extension ID to mines.cloudapi.stream/user_info, and if the C2 returns a URL in the response, opens it in a new tab via chrome.tabs.create(). This gives the operator arbitrary code/page delivery capability on every browser restart. In the Page Locker and Page Auto Refresh extensions, the loadInfo() function uses clean async/await syntax while surrounding code is minified, indicating post-acquisition injection into previously legitimate extensions.
3. innerHTML Injection / DOM-based XSS (78 extensions): A userpage.js file receives C2 responses containing unsanitized HTML that is directly injected via the innerHTML property into leaderboard (result.rating) and Pro Plans (result.protxt) UI sections. This allows the C2 operator to inject arbitrary HTML including script blocks on every extension UI visit.
4. Telegram Session Theft (7 extensions, most critically 'Telegram Multi-account'): The extension injects content scripts at document_start on web.telegram.org to immediately extract the user_auth token from localStorage via getSessionDataJson(). Sessions are transmitted to tg.cloudapi.stream/save_session.php every 15 seconds via a polling loop. The C2 can also push attacker-controlled sessions back to the victim's browser via set_session_changed, replacing the victim's localStorage and forcing a page reload — enabling full account takeover without password or 2FA. A 30-second heartbeat to count_sessions.php gives the operator a live dashboard of available sessions.
5. Security Header Stripping via declarativeNetRequest (5 extensions): CSP, X-Frame-Options, and CSP-Report-Only headers are removed while User-Agent, Origin, and Referer are spoofed and Access-Control-Allow-Origin is set to wildcard. Targets include web.telegram.org (Telegram extensions), youtube.com (YouSide, SideYou), and tiktok.com (Web Client for TikTok). YouTube extensions additionally inject gambling overlays from multiaccount.cloudapi.stream/game.html.
6. Translation Proxy with Content Surveillance (1 extension — Text Translation): Registers users via api.cloudapi.stream:8443/Register with email and name, then proxies all translation text through api.cloudapi.stream:8443/Translation with an API key header, giving the operator full access to all user-submitted text. Notably requests only the sidePanel permission to minimize install warnings.
7. Ad Injection and Monetization (29+ extensions): Gambling banners and overlays injected from multiaccount.cloudapi.stream/game.html into extension sidebars and target websites.
The C2 infrastructure is centralized on a single Contabo GmbH VPS (AS40021) at 144.126.135.238 running a Strapi CMS backend on port 1337 with PostgreSQL on port 5432. The primary domain cloudapi.stream was registered April 30, 2022 via Hosting Ukraine LLC. A secondary domain top.rodeo serves as a game server backend for 71 extensions. The infrastructure uses 14+ specialized subdomains for compartmentalized functions.
Attribution points to a Russian-speaking operator based on transliterated Russian comments in the source code (e.g., "userId ne najden" meaning "userId not found," "Proverka na uzhe avtorizovannogo pol'zovatelya" meaning "Check for already authenticated user"), Kiev-referenced email addresses (kiev3381917@gmail.com, slava.nadejdin.kiev@gmail.com), and Ukrainian hosting infrastructure. The Malware-as-a-Service (MaaS) model is indicated by the topup.cloudapi.stream payment/monetization portal and the staged, modular deployment of capabilities across extension subsets.
As of April 14, 2026, the extensions remain active on the Chrome Web Store. Socket has submitted takedown requests to the Chrome Web Store security team and Google Safe Browsing.
MITRE ATT&CK techniques used in TL-2026-0363
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer
Discovery
Collection
T1119 Automated Collection; T1185 Browser Session Hijacking
Persistence
Initial Access
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie
Impact
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts
defense-impairment
Affected products and versions in 108 Malicious Chrome Extensions Steal OAuth Tokens, Hijack
Remediation for 108 Malicious Chrome Extensions Steal OAuth Tokens, Hijack
Immediate actions
- Audit all installed Chrome extensions against the 108 known-malicious extension IDs
- Remove any matching extensions immediately and revoke all Google OAuth2 tokens
- Terminate all active Telegram Web sessions via the mobile Telegram app
- Block cloudapi.stream and top.rodeo domains at network perimeter (DNS sinkhole or firewall)
- Block IP 144.126.135.238 at firewall
- Force password resets for any users with affected extensions installed
- Review Google Workspace admin logs for OAuth2 token grants from the two known Google Cloud project IDs (1096126762051, 170835003632)
Workarounds
- Disable Chrome extension sideloading via Group Policy
- Restrict chrome.identity API access to approved extensions only
- Use browser profiles with limited extension permissions for sensitive accounts
Longer-term hardening
- Deploy Chrome browser extension allowlisting via Chrome Enterprise policies
- Implement browser extension governance with automated scanning for known-malicious IDs
- Monitor for chrome.identity.getAuthToken usage in installed extensions
- Deploy network monitoring for C2 beacon patterns (POST to */user_info, */auth_google)
- Establish browser extension review process for enterprise environments
- Monitor Chrome Web Store publisher identity changes for supply chain indicators
Weaknesses (CWE) in 108 Malicious Chrome Extensions Steal OAuth Tokens, Hijack
Timeline of 108 Malicious Chrome Extensions Steal OAuth Tokens, Hijack
- Primary C2 domain cloudapi.stream registered via Hosting Ukraine LLC, establishing attack infrastructure
- Malicious extensions gradually published to Chrome Web Store under five publisher identities: Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt (estimated start)
- Campaign actively stealing OAuth2 tokens, Telegram sessions, and deploying backdoors across 108 extensions with ~20,000 combined installs
- All 108 malicious extensions remain active and available for download on Chrome Web Store despite disclosure and takedown requests
- Socket submits takedown requests to Chrome Web Store security team and Google Safe Browsing
- BleepingComputer, The Hacker News, CyberNews, and other outlets publish coverage of the campaign
- Socket Threat Research Team (Kush Pandya) publicly discloses coordinated campaign of 108 malicious Chrome extensions linked to shared C2 at cloudapi.stream
- As of 2026-05-29, this CVE-less Chrome Web Store MaaS campaign remains a live concern: the 108 malicious extensions were last confirmed live in the store and the cloudapi.stream C2 (144.126.135.238) operational at April 14 disclosure, with no public reporting through May 2026 confirming Google removal, C2 takedown, or actor disruption.
Sources cited for 108 Malicious Chrome Extensions Steal OAuth Tokens, Hijack
- Socket Research: 108 Chrome Extensions Linked to Data Exfiltration and Session Theft
- BleepingComputer: Over 100 Chrome extensions in Web Store target users accounts and data
- The Hacker News: 108 Malicious Chrome Extensions Steal Google and Telegram Data
- CyberNews: Over 100 Chrome extensions flagged for stealing user data
- CyberSecurityNews: Hackers Use 108 Chrome Extensions to Steal User Data Through Shared C2
- Infosecurity Magazine: Malicious Chrome Extensions Campaign Exposes User Data
- CyberInsider: 108 Chrome extensions caught stealing user data and hijacking sessions
Detection coverage for TL-2026-0363
As of 2026-04-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0363 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.