Researchers have identified 152 malicious Google Chrome extensions disguised as live wallpaper add-ons that are actively harvesting user data and engaging in sophisticated traffic-attribution fraud across 105,000 installations.
Key Points
- The malicious network spans 38 publisher accounts and three primary brand backends: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com.
- Extensions falsely claim to protect user privacy while secretly logging IP addresses, ISP details, and click counts for third-party ad partners.
- The software uses hard-coded JavaScript to fabricate "organic" Google search traffic by manipulating install and uninstall redirect URLs.
- A dormant feature within the extensions allows them to enumerate and delete IndexedDB databases stored on a user's browser.
- Security analysts categorize the campaign as a financially motivated adware operation, with evidence suggesting a potential origin in Turkey.