108 Chrome extensions trapped, your Google and Telegram too
108 malicious Chrome extensions identified in the Chrome Web Store by Socket researchers. Google OAuth theft, backdoors, Telegram exfiltration. Google notified, extensions still online at publication. If you're using Chrome on Mac, you're affected.
Mid-April 2026, Socket researchers identify 108 malicious Chrome extensions in the Chrome Web Store, with around 20,000 cumulative installations. Google OAuth theft, universal backdoors, Telegram exfiltration. Extensions were still online at the time of public disclosure. If you’re using Chrome on Mac, and most Mac users are, you’re directly affected.
What’s happening
Socket researchers found 108 extensions published in the Chrome Web Store under five different publisher aliases (Yana Project, GameGen, SideGames, Rodeo Games, InterAlt) to throw off suspicion. Public disclosure on April 13, 2026. Extensions remained online despite Google’s notification.
The haul is varied and precise enough for mass work. 54 extensions retrieved Google OAuth tokens, those little keys that let a third-party service access your Google account without you re-entering your password.
Another 45 contained a universal backdoor that opens arbitrary URLs upon browser launch, perfect for pushing phishing or malicious content on demand.
And one dedicated extension exfiltrated Telegram Web session tokens every 15 seconds, draining localStorage to a command server. Enough to steal a messaging account without you even noticing.
Around 20,000 cumulative installations. That’s industrial-scale harvesting.
Why it matters to you
No macOS 0-day in this case. No Apple Silicon flaw, no Gatekeeper bypass. The vector is Chrome, and the extensions ecosystem running on it.
And Chrome, on Mac, is the default browser for a significant portion of users, including professionals who keep Safari for the rest. You sync your tabs with Google, let Chrome handle your autofill, install three extensions for your workflow, and forget about it.
Extensions have access to your tabs, cookies, and form data. When one becomes malicious, it can read what you’re reading. Here, the domino effect is brutal.
A stolen Google OAuth token means potential access to Gmail, Drive, Photos, Calendar, depending on the granted scopes. An exfiltrated Telegram token means access to your conversations, groups, channels, shared files. No need for your password: the token is the session, and the session opens the door.
The Chrome Web Store isn’t the App Store. Google reviews extensions, but not with the same level of rigor as Apple. Bad extensions slip through, and they often slip through often.
What you need to do
Practically:
1. Open Chrome, go to chrome://extensions, and disable everything you don’t use daily. Extensions that have been lying around for two years are exactly the attack surface you want to reduce.
2. Log in to myaccount.google.com, Security section, then Your Devices. Sign out any sessions you don’t recognize. While you’re at it, check the third-party apps accessing your Google account and revoke any you don’t recognize.
3. On Telegram, go to Settings then Devices (or Active Sessions depending on the client). Close all sessions except the one you’re using. If you see a session from a country or device you don’t recognize, it’s already too late for that session, but you can still cut off the flow.
4. Think about making Safari your default browser on Mac. Fewer extensions available means less attack surface. Safari doesn’t magically protect you, but its extension model is more restrictive, and Apple controls distribution via the Mac App Store for most of them.
And the bottom line, beyond this incident: a browser extension sees everything your browser sees. Install them like you’d install a system app, that is, with caution and restraint.
Technical terms? Check the glossary.
Sources
- Socket Threat Research Team, 108 Chrome Extensions Linked to Data Exfiltration, Session Theft, Shared C2, April 13, 2026
- CyberInsider, 108 Chrome Extensions Caught Stealing User Data and Hijacking Sessions, April 14, 2026