Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection
Coordinated Campaign of 32 Malicious Chrome/Edge (TL-2026-2821) is a medium-severity malware campaign, first published 2026-10-01. It has no confirmed attribution, affects Google Chrome Web Store extensions (Chrome users), maps to 9 MITRE ATT&CK techniques (T1027.013, T1036.005, T1071.001), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-2821
- Threat ID
- TL-2026-2821
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-10-01
- Last reviewed
- 2026-10-01
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- consumer, technology, ecommerce
- Target regions
- south korea, Global
- Detection rules
- 9
- Indicators of compromise
- 27
Akamai (LayerX Research) reports a coordinated campaign of 32 malicious browser extensions on the Chrome Web Store and Microsoft Edge Add-ons Store, installed by 6,150+ users. The extensions pose as productivity tools but monitor browsing and redirect tabs, driven by attacker-controlled remote configuration; artifacts point to Korean-speaking operator(s) and Coupang affiliate-fraud monetization.
How Coordinated Campaign of 32 Malicious Chrome/Edge works
Akamai Security Research (Natalie Zagarov, published 2026-09-30) documents a family of 32 browser extensions published to the Chrome Web Store and Microsoft Edge Add-ons Store since March 2025, with ongoing development and new variants published over subsequent months. The extensions are branded as ordinary utilities: Youtube Detox, Eye Rest Reminder, Quick Memo, KoreaDropdown, Language Learning, YouTube Summary, SnapShot, Copy as Markdown, YouTube Enhancer, SEO Toolkit, Text Counter, Web Highlighter, Page Ruler, Video Speed Controller, Tab Manager, Scroll to Top, Holiday D-day, Reaction Time Test, Reading Time, Image Downloader, Auto Scroll, Air Quality Monitor and GitHub Korean (the largest at about 4,000 installs). Total reach is over 6,150 users.
Despite different branding, the variants share one background service worker implementation, identical telemetry events and storage structures, and common navigation logic. They request broad permissions (<all_urls>, webNavigation, tabs, session storage and chrome.tabs.update()), which are unrelated to their advertised functions.
At runtime each extension retrieves an attacker-controlled configuration from a GitHub-hosted file served via the jsDelivr CDN (cdn.jsdelivr.net/gh/chosanghyeon-dev/chosanghyeon-dev@main/cf.json), with a secondary Cloudflare Workers endpoint (api.pvmf.workers.dev) identified as command-and-control infrastructure. Hostnames, redirect targets and identifiers in the config are Base64-encoded and decoded in the extension. Because behavior is driven by external configuration, the operator can change it without a store update; Akamai observed configuration changes including temporary empty states and new affiliate rules.
The extensions continuously watch browsing activity through the webNavigation API (onCompleted event) and, when the remote rules match, rebuild a destination URL from the config and redirect the tab using chrome.tabs.update(). Observed redirect targets are two Coupang affiliate short links (link.coupang.com/a/dUnRI6 and link.coupang.com/a/ej6z6U), indicating affiliate-fraud monetization. Akamai notes the same infrastructure could support broader malicious navigation manipulation.
Attribution is limited to Korean-speaking actor(s): Korean-language identifiers, embedded Korean localization resources and Korean development comments, a Korean-market affiliate program, and an associated email (indie05hacker@gmail.com) and GitHub account (chosanghyeon-dev). The public GitHub profile lists a Seoul location and UTC+9 timezone. The profile's ownership is not independently verified, and it could be a compromised or impersonated account. Severity is analyst-assigned (no CVE/CVSS). At analyst check on 2026-10-01 the jsDelivr cf.json URL returned HTTP 404 and BeaconBeagle returned no config match for api.pvmf.workers.dev.
MITRE ATT&CK techniques used in TL-2026-2821
Defense Evasion
T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information
Command and Control
T1071.001 Web Protocols; T1102.001 Dead Drop Resolver
Persistence
Initial Access
Impact
T1565.002 Transmitted Data Manipulation
Resource Development
Affected products and versions in Coordinated Campaign of 32 Malicious Chrome/Edge
- Google — Chrome Web Store extensions (Chrome users)
Vulnerable versions: 32-extension family; see IOC extension IDs - Microsoft — Microsoft Edge Add-ons Store extensions (Edge users)
Vulnerable versions: 32-extension family; see IOC extension IDs
Remediation for Coordinated Campaign of 32 Malicious Chrome/Edge
Immediate actions
- Remove the 32 listed extensions (match by extension ID) from Chrome and Edge profiles
- Block or alert on requests to api.pvmf.workers.dev and the chosanghyeon-dev jsDelivr path
- Review browser inventory for extensions requesting <all_urls>, webNavigation and tabs that are unrelated to their stated function
Workarounds
- Remove unnecessary extensions with broad permissions
- Restrict extension installation to approved IDs
Longer-term hardening
- Enforce an extension allowlist via Chrome/Edge enterprise policy
- Monitor for extensions that retrieve remote configuration and manipulate navigation
- Treat remotely controlled extensions as persistent attack platforms
Timeline of Coordinated Campaign of 32 Malicious Chrome/Edge
- Campaign active since March 2025 (month-level precision per Akamai); first extensions published to the Chrome Web Store and Edge Add-ons Store
- New extension variants published continuously in the months after launch; the remote config was observed changing (temporary empty states, new affiliate rules). Date is a placeholder for an undated interval
- Akamai announced intent to acquire LayerX (May 2026); the research is published under Akamai Security Research from the LayerX team
- Campaign described as ongoing at publication; extensions still being developed
- Akamai published 'When Productivity Extensions Become Attack Platforms', disclosing 32 extensions, 6,150+ users and the shared remote-config infrastructure
- Analyst check: jsDelivr cf.json URL returned HTTP 404 and BeaconBeagle config search for api.pvmf.workers.dev returned no matches
Sources cited for Coordinated Campaign of 32 Malicious Chrome/Edge
- When Productivity Extensions Become Attack Platforms (Akamai)
- GitHub profile chosanghyeon-dev (config host account)
- MITRE ATT&CK T1176.001 Browser Extensions
- MITRE ATT&CK T1565.002 Transmitted Data Manipulation
- MITRE ATT&CK T1102.001 Dead Drop Resolver
- LayerX: Akamai acquires LayerX (research-team context)
More in malware
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
Detection coverage for TL-2026-2821
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2821 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.