
- Socket finds 108 malicious Chrome extensions stealing tokens and data
- Extensions harvest Google account info, hijack Telegram sessions, and open backdoors
- Likely Russian MaaS operation; 20,000+ installs, still live in Web Store
A single threat actor has apparently smuggled more than 100 malicious browser extensions into the official Google Chrome Web Store, looking to steal authentication tokens, and establish backdoors to people’s devices.