Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Over 300 Malicious Chrome Extensions Caught Leaking or Stealing User Data
    Cybersecurity

    Over 300 Malicious Chrome Extensions Caught Leaking or Stealing User Data

    adminBy adminFebruary 14, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Chrome security
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Security researchers have discovered more than 300 Chrome extensions that leak browser data, spy on their users, or outright steal users’ data.

    Research focused on the analysis of network traffic generated by Chrome extensions has uncovered 287 applications transmitting the user’s browsing history or search engine results pages (SERP).

    Some of them, security researcher Q Continuum explains, would essentially expose the data to unsecured networks, while others would send it to collection servers, either due to intended functionality, for monetization purposes, or with malicious intent.

    The extensions have over 37.4 million users, the researcher says. Of these, roughly 27.2 million users installed 153 extensions that were confirmed to leak browser history upon installation.

    Q Continuum, who also flagged over 200 additional extensions as suspicious due to shared author details with the data-leaking ones, observed four scrapers connecting to the honeypot set up for the research.

    Based on the observations, the researcher believes that a data broker rather than extension developers might be directly involved in the monetization of these applications.

    Advertisement. Scroll to continue reading.

    The researcher has linked the extensions to 32 entities and has uncovered connections to known distributors of spyware extensions.

    In a separate report, LayerX has detailed the malicious behavior of 30 Chrome extensions with over 260,000 downloads that were seen injecting iframes to manipulate content and steal users’ browser data.

    Posing as AI assistance tools, all extensions had “the same internal structure, JavaScript logic, permissions, and backend infrastructure”, suggesting they are part of a single, coordinated operation.

    One extension would render a full screen iframe pointing to a remote domain and allowing the attacker to load remote content to manipulate the UI directly.

    The extension can also extract data from the active tab, supports message-triggered voice recognition, and includes explicit tracking pixel scripts.

    According to LayerX, 15 extensions were seen specifically targeting Gmail, extracting email content and transmitting it to third-party infrastructure.

    Related: Malicious Chrome Extension Crashes Browser in ClickFix Variant ‘CrashFix’

    Related: Chrome, Edge Extensions Caught Stealing ChatGPT Sessions

    Related: GhostPoster Firefox Extensions Hide Malware in Icons

    Related: Chrome, Edge Extensions Caught Tracking Users, Creating Backdoors

    Caught Chrome data Extensions leaking Malicious stealing user
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous Article5 open-source apps that are so good their premium versions are worth paying for
    Next Article ‘I’m grieving’: OpenAI has switched off ChatGPT-4o, and angry users are backing a #keep4o campaign to restore it
    admin
    • Website

    Related Posts

    Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery

    April 18, 2026

    Critical flaw in Protobuf library enables JavaScript code execution

    April 18, 2026

    Dive Into The Stanford Report Data

    April 18, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    U.S. search ad revenue reached $114.2 billion in 2025

    April 18, 2026

    You Should Start Spring Cleaning With This Dyson Cordless Vacuum While It’s on Sale for Over $200 Off

    April 18, 2026

    Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery

    April 18, 2026

    Critical flaw in Protobuf library enables JavaScript code execution

    April 18, 2026
    Categories
    • Blogging (65)
    • Cybersecurity (1,385)
    • Privacy & Online Earning (171)
    • SEO & Digital Marketing (848)
    • Tech Tools & Mobile / Apps (1,654)
    • WiFi / Internet & Networking (232)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    U.S. search ad revenue reached $114.2 billion in 2025

    April 18, 2026

    You Should Start Spring Cleaning With This Dyson Cordless Vacuum While It’s on Sale for Over $200 Off

    April 18, 2026

    Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery

    April 18, 2026
    Most Popular
    • U.S. search ad revenue reached $114.2 billion in 2025
    • You Should Start Spring Cleaning With This Dyson Cordless Vacuum While It’s on Sale for Over $200 Off
    • Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery
    • Critical flaw in Protobuf library enables JavaScript code execution
    • Dive Into The Stanford Report Data
    • Claude Cowork took one repetitive task for me, and I’m very impressed
    • Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
    • ConnectBot v1.10.4 by Kenny Root
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.