Last Update: 09/22/2026 at 11:34 PM EST

Malicious Extensions Hijack Browser Sessions

Coverage from BleepingComputer, SecurityWeek, and others

Malicious Extensions Hijack Browser Sessions topic image

Malicious browser extensions are being used as a durable access layer for credential theft, session hijacking, ad fraud, remote code execution, and abuse of authenticated web services.

Campaigns affecting Chrome and Edge have used legitimate-looking functionality, delayed or concealed payloads, shared infrastructure, and multiple publisher identities to reach large user populations. The pattern shows that browser add-ons can convert ordinary browsing access into persistent control over identity data, messaging sessions, enterprise credentials, and connected applications.

Looking Back
96 Day Timeline
Apr 14May 5May 19Jun 9Jun 23Jul 14
History
07/23/2026

The story now emphasizes browser extensions as a broader, more durable access layer for multiple forms of abuse, rather than mainly a credential-theft and session-hijacking threat. It also adds a sharper finding that some malicious extensions were still present in official stores when disclosed, underscoring the persistence of trusted-channel abuse.

07/21/2026

The story expands beyond store-distributed browser-extension malware to include a new delivery chain, ACR Stealer, and a separate Claude for Chrome flaw that lets extensions trigger authenticated AI workflows. It also sharpens the scale and technical sophistication of the extension campaigns, especially StegoAd’s install base and concealed execution methods.

All Articles7 articles
Additional7 articles · CI Score below 45
BleepingComputer / Bill Toulas
4/14/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
7/18/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Lawrence Abrams
7/16/2026 • Cybersecurity (Privacy-Relevant) • General
SecurityWeek / Ionut Arghire
4/17/2026 • Cybersecurity (Privacy-Relevant) • General
Let's Data Science
6/30/2026 • Cybersecurity (Privacy-Relevant) • General
Security Affairs / Pierluigi Paganini
6/29/2026 • Cybersecurity Tech (Privacy-Relevant) • General
Security Affairs / Pierluigi Paganini
6/29/2026 • Cybersecurity Tech (Privacy-Relevant) • General