Malicious Extensions Hijack Browser Sessions
Coverage from BleepingComputer, SecurityWeek, and others

Malicious browser extensions are being used as a durable access layer for credential theft, session hijacking, ad fraud, remote code execution, and abuse of authenticated web services.
Campaigns affecting Chrome and Edge have used legitimate-looking functionality, delayed or concealed payloads, shared infrastructure, and multiple publisher identities to reach large user populations. The pattern shows that browser add-ons can convert ordinary browsing access into persistent control over identity data, messaging sessions, enterprise credentials, and connected applications.
The story now emphasizes browser extensions as a broader, more durable access layer for multiple forms of abuse, rather than mainly a credential-theft and session-hijacking threat. It also adds a sharper finding that some malicious extensions were still present in official stores when disclosed, underscoring the persistence of trusted-channel abuse.
The story expands beyond store-distributed browser-extension malware to include a new delivery chain, ACR Stealer, and a separate Claude for Chrome flaw that lets extensions trigger authenticated AI workflows. It also sharpens the scale and technical sophistication of the extension campaigns, especially StegoAd’s install base and concealed execution methods.
