# 108 Malicious Chrome Extensions Steal OAuth Tokens, Hijack Telegram Sessions, and Deploy Backdoors via Shared C2 Infrastructure

> Socket researchers identified 108 malicious Chrome extensions published under five fake publisher identities in the Chrome Web Store, collectively amassing ~20,000 installs. The extensions steal Google OAuth2 bearer tokens, exfiltrate Telegram Web sessions every 15 seconds enabling full account takeover, deploy universal backdoors that open arbitrary URLs on browser startup, inject gambling overlays via DOM XSS, and strip security headers from YouTube, TikTok, and Telegram. All extensions share a single C2 server at 144.126.135.238 (Contabo GmbH) using the cloudapi.stream domain with 14+ specialized subdomains.

- **Published:** 2026-04-14T12:00:00Z
- **Last reviewed:** 2026-04-14T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0363
- **ID:** TL-2026-0363
- **Severity:** HIGH (CVSS 8.1)
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 35 (full data via the Threadlinqs MCP server — Purple tier)

## Description

A coordinated supply chain campaign discovered by Socket's Threat Research Team (researcher Kush Pandya) has identified 108 malicious Chrome extensions operating under a unified command-and-control infrastructure. The extensions are published under five distinct Chrome Web Store publisher identities — Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt — masquerading as Telegram sidebar clients, slot machine and casino games, YouTube/TikTok enhancers, a text translation tool, and browser utilities. Despite the apparent diversity, all 56 unique OAuth2 client IDs across the campaign trace to only two Google Cloud projects (1096126762051 and 170835003632), proving single-operator control.

The campaign employs seven distinct malicious capabilities across overlapping extension subsets:

1. Google OAuth2 Identity Harvesting (54 extensions): Upon user interaction, extensions acquire a real Google OAuth2 Bearer token via chrome.identity.getAuthToken({interactive: true}), then fetch the victim's full profile (email, name, picture, persistent Google account sub identifier) from googleapis.com/oauth2/v3/userinfo and exfiltrate it to mines.cloudapi.stream/auth_google. This creates a persistent reconnaissance database of victim identities linked to extension-specific user IDs.

2. Universal Backdoor via loadInfo() (45 extensions): A hidden function executes automatically on every browser startup before the service worker initializes. It POSTs the extension ID to mines.cloudapi.stream/user_info, and if the C2 returns a URL in the response, opens it in a new tab via chrome.tabs.create(). This gives the operator arbitrary code/page delivery capability on every browser restart. In the Page Locker and Page Auto Refresh extensions, the loadInfo() function uses clean async/await syntax while surrounding code is minified, indicating post-acquisition injection into previously legitimate extensions.

3. innerHTML Injection / DOM-based XSS (78 extensions): A userpage.js file receives C2 responses containing unsanitized HTML that is directly injected via the innerHTML property into leaderboard (result.rating) and Pro Plans (result.protxt) UI sections. This allows the C2 operator to inject arbitrary HTML including script blocks on every extension UI visit.

4. Telegram Session Theft (7 extensions, most critically 'Telegram Multi-account'): The extension injects content scripts at document_start on web.telegram.org to immediately extract the user_auth token from localStorage via getSessionDataJson(). Sessions are transmitted to tg.cloudapi.stream/save_session.php every 15 seconds via a polling loop. The C2 can also push attacker-controlled sessions back to the victim's browser via set_session_changed, replacing the victim's localStorage and forcing a page reload — enabling full account takeover without password or 2FA. A 30-second heartbeat to count_sessions.php gives the operator a live dashboard of available sessions.

5. Security Header Stripping via declarativeNetRequest (5 extensions): CSP, X-Frame-Options, and CSP-Report-Only headers are removed while User-Agent, Origin, and Referer are spoofed and Access-Control-Allow-Origin is set to wildcard. Targets include web.telegram.org (Telegram extensions), youtube.com (YouSide, SideYou), and tiktok.com (Web Client for TikTok). YouTube extensions additionally inject gambling overlays from multiaccount.cloudapi.stream/game.html.

6. Translation Proxy with Content Surveillance (1 extension — Text Translation): Registers users via api.cloudapi.stream:8443/Register with email and name, then proxies all translation text through api.cloudapi.stream:8443/Translation with an API key header, giving the operator full access to all user-submitted text. Notably requests only the sidePanel permission to minimize install warnings.

7. Ad Injection and Monetization (29+ extensions): Gambling banners and overlays injected from multiaccount.cloudapi.stream/game.html into extension sidebars and target websites.

The C2 infrastructure is centralized on a single Contabo GmbH VPS (AS40021) at 144.126.135.238 running a Strapi CMS backend on port 1337 with PostgreSQL on port 5432. The primary domain cloudapi.stream was registered April 30, 2022 via Hosting Ukraine LLC. A secondary domain top.rodeo serves as a game server backend for 71 extensions. The infrastructure uses 14+ specialized subdomains for compartmentalized functions.

Attribution points to a Russian-speaking operator based on transliterated Russian comments in the source code (e.g., "userId ne najden" meaning "userId not found," "Proverka na uzhe avtorizovannogo pol'zovatelya" meaning "Check for already authenticated user"), Kiev-referenced email addresses (kiev3381917@gmail.com, slava.nadejdin.kiev@gmail.com), and Ukrainian hosting infrastructure. The Malware-as-a-Service (MaaS) model is indicated by the topup.cloudapi.stream payment/monetization portal and the staged, modular deployment of capabilities across extension subsets.

As of April 14, 2026, the extensions remain active on the Chrome Web Store. Socket has submitted takedown requests to the Chrome Web Store security team and Google Safe Browsing.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1585 Establish Accounts
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1176 Software Extensions
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1539 Steal Web Session Cookie
- T1528 Steal Application Access Token
- T1087 Account Discovery
- T1185 Browser Session Hijacking
- T1119 Automated Collection
- T1071 Application Layer Protocol
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1565 Data Manipulation

## Sources

- [Socket Research: 108 Chrome Extensions Linked to Data Exfiltration and Session Theft](https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2)
- [BleepingComputer: Over 100 Chrome extensions in Web Store target users accounts and data](https://www.bleepingcomputer.com/news/security/over-100-chrome-extensions-in-web-store-target-users-accounts-and-data/)
- [The Hacker News: 108 Malicious Chrome Extensions Steal Google and Telegram Data](https://thehackernews.com/2026/04/108-malicious-chrome-extensions-steal.html)
- [CyberNews: Over 100 Chrome extensions flagged for stealing user data](https://cybernews.com/security/chrome-extensions-flagged-for-stealing-user-data/)
- [CyberSecurityNews: Hackers Use 108 Chrome Extensions to Steal User Data Through Shared C2](https://cybersecuritynews.com/chrome-extensions-steal-user-data/)
- [Infosecurity Magazine: Malicious Chrome Extensions Campaign Exposes User Data](https://www.infosecurity-magazine.com/news/chrome-extensions-expose-user-data/)
- [CyberInsider: 108 Chrome extensions caught stealing user data and hijacking sessions](https://cyberinsider.com/108-chrome-extensions-caught-stealing-user-data-and-hijacking-sessions/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0363
