Daily Guardian UAEDaily Guardian UAE
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
What's On

Instagram’s teen crackdown moves from DMs to feeds

May 14, 2026

Invest Bank Reports 97% Profit Growth in Q1 2026

May 14, 2026

Meta says WhatsApp is now the safest app to chat… with an AI

May 14, 2026

I’m still not sold on a disc-less Xbox, but Project Helix feels inevitable now

May 14, 2026

At $4,499, the Sony A7R VI undercuts the A1 II by $2,000, and still matches it at 30fps

May 14, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian UAE
Subscribe
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
Daily Guardian UAEDaily Guardian UAE
Home » Over a hundred Chrome extensions discovered raising hell. Check out if you’ve been using one
Technology

Over a hundred Chrome extensions discovered raising hell. Check out if you’ve been using one

By dailyguardian.aeApril 16, 20263 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

More than 100 Chrome extensions have been tied to a sprawling campaign that harvested identity data, opened backdoor-style browser behavior, and in one case pulled live Telegram Web session data. Researchers linked 108 add-ons to the same control network, with about 20,000 installs logged across the Chrome Web Store when the findings were published.

What makes this one hit harder is the range. The extensions showed up as Telegram tools, slot and Keno games, translation utilities, YouTube and TikTok helpers, and basic page tools, which helped the operation blend into the kind of stuff people install without much thought. See the full list here.

Researchers said the extensions were still live when the report went up, and takedown requests had already been filed. That gives this story a very practical edge for Chrome users who haven’t checked their add-ons in a while.

The worst behavior wasn’t all the same

The damage wasn’t limited to one trick. The research found that 54 extensions collected Google account identity details after a user clicked a sign-in button, while one Telegram-focused extension exfiltrated active Telegram Web session data every 15 seconds. Another 45 included a routine that could open arbitrary URLs whenever Chrome started, even if the user never opened the extension that day.

Other add-ons stripped security protections from sites like Telegram, YouTube, and TikTok before injecting overlays, ads, or scripts into pages. One translation tool also routed submitted text through the operator’s server, turning a simple helper into a surveillance risk.

Why this should worry regular Chrome users

The bigger issue is how ordinary the bait looked. These weren’t just obscure tools for power users. The list included games, browser helpers, sidebar clients, and translation add-ons, exactly the kind of extras people grab because the store page looks polished and the feature seems useful.

online privacy

Extensions also tend to fade into the background once they’re installed. In this case, researchers traced activity from that mixed bag of tools back to the same backend infrastructure, which turned a random-looking pile of add-ons into one operation with several ways to collect data or alter the browsing experience.

Check your extensions now

The smartest next move is to audit what’s installed in Chrome, especially anything tied to Telegram, lightweight games, translation, or sidebar utilities that asked for sign-in access without a clear reason. The research lists 108 extensions by name and ID, and recommends removing any match immediately.

The highest-risk case appears to be the Telegram extension that repeatedly exfiltrated web session data. Anyone who used it while logged into Telegram Web should terminate other Telegram sessions from the mobile app, and users who signed into one of the Google-linked extensions should review account access and revoke anything unfamiliar.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

Instagram’s teen crackdown moves from DMs to feeds

Meta says WhatsApp is now the safest app to chat… with an AI

I’m still not sold on a disc-less Xbox, but Project Helix feels inevitable now

At $4,499, the Sony A7R VI undercuts the A1 II by $2,000, and still matches it at 30fps

Assassin’s Creed Hexe leak predicts the return of a legendary hero and I can’t wait for it

Qualcomm leak suggests we have entered the ludicrous era of pricey phones

I played like a rat in Arc Raiders, and the loot was disgustingly good

New Backrooms trailer proves it might finally be the horror movie that gets creepypasta right

Apple’s 2028 iPhone display sounds impossible, but Samsung and LG are scrambling to build it

Editors Picks

Invest Bank Reports 97% Profit Growth in Q1 2026

May 14, 2026

Meta says WhatsApp is now the safest app to chat… with an AI

May 14, 2026

I’m still not sold on a disc-less Xbox, but Project Helix feels inevitable now

May 14, 2026

At $4,499, the Sony A7R VI undercuts the A1 II by $2,000, and still matches it at 30fps

May 14, 2026

Subscribe to News

Get the latest UAE news and updates directly to your inbox.

Latest Posts

Assassin’s Creed Hexe leak predicts the return of a legendary hero and I can’t wait for it

May 14, 2026

Qualcomm leak suggests we have entered the ludicrous era of pricey phones

May 14, 2026

I played like a rat in Arc Raiders, and the loot was disgustingly good

May 14, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian UAE. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.