Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection

Coordinated Campaign of 32 Malicious Chrome/Edge (TL-2026-2821) is a medium-severity malware campaign, first published 2026-10-01. It has no confirmed attribution, affects Google Chrome Web Store extensions (Chrome users), maps to 9 MITRE ATT&CK techniques (T1027.013, T1036.005, T1071.001), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-2821

Threat ID
TL-2026-2821
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
2026-10-01
Last reviewed
2026-10-01
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
consumer, technology, ecommerce
Target regions
south korea, Global
Detection rules
9
Indicators of compromise
27

Akamai (LayerX Research) reports a coordinated campaign of 32 malicious browser extensions on the Chrome Web Store and Microsoft Edge Add-ons Store, installed by 6,150+ users. The extensions pose as productivity tools but monitor browsing and redirect tabs, driven by attacker-controlled remote configuration; artifacts point to Korean-speaking operator(s) and Coupang affiliate-fraud monetization.

How Coordinated Campaign of 32 Malicious Chrome/Edge works

Akamai Security Research (Natalie Zagarov, published 2026-09-30) documents a family of 32 browser extensions published to the Chrome Web Store and Microsoft Edge Add-ons Store since March 2025, with ongoing development and new variants published over subsequent months. The extensions are branded as ordinary utilities: Youtube Detox, Eye Rest Reminder, Quick Memo, KoreaDropdown, Language Learning, YouTube Summary, SnapShot, Copy as Markdown, YouTube Enhancer, SEO Toolkit, Text Counter, Web Highlighter, Page Ruler, Video Speed Controller, Tab Manager, Scroll to Top, Holiday D-day, Reaction Time Test, Reading Time, Image Downloader, Auto Scroll, Air Quality Monitor and GitHub Korean (the largest at about 4,000 installs). Total reach is over 6,150 users.

Despite different branding, the variants share one background service worker implementation, identical telemetry events and storage structures, and common navigation logic. They request broad permissions (<all_urls>, webNavigation, tabs, session storage and chrome.tabs.update()), which are unrelated to their advertised functions.

At runtime each extension retrieves an attacker-controlled configuration from a GitHub-hosted file served via the jsDelivr CDN (cdn.jsdelivr.net/gh/chosanghyeon-dev/chosanghyeon-dev@main/cf.json), with a secondary Cloudflare Workers endpoint (api.pvmf.workers.dev) identified as command-and-control infrastructure. Hostnames, redirect targets and identifiers in the config are Base64-encoded and decoded in the extension. Because behavior is driven by external configuration, the operator can change it without a store update; Akamai observed configuration changes including temporary empty states and new affiliate rules.

The extensions continuously watch browsing activity through the webNavigation API (onCompleted event) and, when the remote rules match, rebuild a destination URL from the config and redirect the tab using chrome.tabs.update(). Observed redirect targets are two Coupang affiliate short links (link.coupang.com/a/dUnRI6 and link.coupang.com/a/ej6z6U), indicating affiliate-fraud monetization. Akamai notes the same infrastructure could support broader malicious navigation manipulation.

Attribution is limited to Korean-speaking actor(s): Korean-language identifiers, embedded Korean localization resources and Korean development comments, a Korean-market affiliate program, and an associated email (indie05hacker@gmail.com) and GitHub account (chosanghyeon-dev). The public GitHub profile lists a Seoul location and UTC+9 timezone. The profile's ownership is not independently verified, and it could be a compromised or impersonated account. Severity is analyst-assigned (no CVE/CVSS). At analyst check on 2026-10-01 the jsDelivr cf.json URL returned HTTP 404 and BeaconBeagle returned no config match for api.pvmf.workers.dev.

MITRE ATT&CK techniques used in TL-2026-2821

Defense Evasion

T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information

Command and Control

T1071.001 Web Protocols; T1102.001 Dead Drop Resolver

Persistence

T1176.001 Browser Extensions

Initial Access

T1199 Trusted Relationship

Impact

T1565.002 Transmitted Data Manipulation

Resource Development

T1583.006 Web Services

Affected products and versions in Coordinated Campaign of 32 Malicious Chrome/Edge

  • Google — Chrome Web Store extensions (Chrome users)
    Vulnerable versions: 32-extension family; see IOC extension IDs
  • Microsoft — Microsoft Edge Add-ons Store extensions (Edge users)
    Vulnerable versions: 32-extension family; see IOC extension IDs

Remediation for Coordinated Campaign of 32 Malicious Chrome/Edge

Immediate actions

  • Remove the 32 listed extensions (match by extension ID) from Chrome and Edge profiles
  • Block or alert on requests to api.pvmf.workers.dev and the chosanghyeon-dev jsDelivr path
  • Review browser inventory for extensions requesting <all_urls>, webNavigation and tabs that are unrelated to their stated function

Workarounds

  • Remove unnecessary extensions with broad permissions
  • Restrict extension installation to approved IDs

Longer-term hardening

  • Enforce an extension allowlist via Chrome/Edge enterprise policy
  • Monitor for extensions that retrieve remote configuration and manipulate navigation
  • Treat remotely controlled extensions as persistent attack platforms

Timeline of Coordinated Campaign of 32 Malicious Chrome/Edge

  • Campaign active since March 2025 (month-level precision per Akamai); first extensions published to the Chrome Web Store and Edge Add-ons Store
  • New extension variants published continuously in the months after launch; the remote config was observed changing (temporary empty states, new affiliate rules). Date is a placeholder for an undated interval
  • Akamai announced intent to acquire LayerX (May 2026); the research is published under Akamai Security Research from the LayerX team
  • Campaign described as ongoing at publication; extensions still being developed
  • Akamai published 'When Productivity Extensions Become Attack Platforms', disclosing 32 extensions, 6,150+ users and the shared remote-config infrastructure
  • Analyst check: jsDelivr cf.json URL returned HTTP 404 and BeaconBeagle config search for api.pvmf.workers.dev returned no matches

Sources cited for Coordinated Campaign of 32 Malicious Chrome/Edge

More in malware

Detection coverage for TL-2026-2821

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2821 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats