•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•

Socket reports that a network of 108 Chrome extensions in the Chrome Web Store has been found to establish backdoors and steal data. The extensions were disguised as widely used tools, including a Telegram session manager, a YouTube UI optimizer, TikTok-related tools, mini-games, and a translation utility. Researchers say the operation is run by five developer entities—Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt—but all connect to a single command-and-control (C2) server.
By the time of discovery, the tools had already infiltrated and stolen data from thousands of user accounts, indicating a coordinated data-theft scheme with a clear objective.
Technical analysis indicates the attackers did not only collect basic information; they also targeted deep user access:
Researchers say the extensions request excessive access to webpage data, which can allow injection of malicious code to monitor user behavior and exfiltrate sensitive information.
Although Google maintains that the Chrome Web Store is a safe environment, researchers report that more than 100 extensions sharing a similar malicious code structure slipped through the review process. They note that while the extensions have different names and functions, they all send data to the same command-and-control IP address.
The presence of a central C2 server suggests the activity is not isolated, but part of a coordinated campaign designed to maximize the amount of data stolen from Chrome users.
The incident highlights that browsers can store key elements of users’ digital lives, making careful extension management important.
Researchers recommend the following steps:
Premium gym chains are entering a “golden era” that is ending or already in decline, as rising operating costs collide with shifting consumer preferences toward more flexible, community-based ways to exercise. Long-term memberships are shrinking, margins are pressured by higher rents and facility expenses, and competition from smaller, more personalized…