Skip to content
MalwareContained

152 'live wallpaper' Chrome extensions caught harvesting user data and faking Google search traffic

Socket's Threat Research Team uncovered a coordinated family of 152 new-tab 'live wallpaper' Chrome extensions, spread across 38 publisher accounts and three brands, that secretly logged user telemetry and laundered extension-generated visits into fake Google organic search traffic despite declaring they collected no data.

Victim
Google Chrome Web Store users
users
105.0K

On 13 June 2026, Socket's Threat Research Team disclosed a coordinated family of 152 "live wallpaper" new-tab extensions on the Google Chrome Web Store that secretly logged user data and manufactured fake Google "organic search" traffic β€” all while their store listings explicitly promised they collected no data at all.

What happened

The extensions were built from a single shared codebase but distributed across 38 publisher accounts and three brands β€” tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com (which redirects to owhit[.]com) β€” to spread the campaign across many listings and blunt the impact of any single takedown. Using popular themes such as anime, games, football and car wallpapers to attract installs, the extensions together reported roughly 105,000 users.

Despite each Chrome Web Store listing declaring that no user data was collected, the extensions aggressively harvested telemetry in the background. The operator's own external privacy policy contradicted those listings, admitting to logging IP addresses, internet service provider (ISP) data, click counts and referrer data. Rather than injecting ads into arbitrary websites, the extensions redirected users to operator-controlled, programmatically monetised domains.

Why it matters

This adware-adjacent campaign abused new-tab extensions to launder extension-generated visits into what looked like legitimate Google organic search traffic, polluting analytics for advertisers and Google alike while quietly profiting from the redirected clicks. The gap between the "no data collected" store labels and the operator's actual privacy policy highlights how easily Chrome Web Store disclosures can be gamed β€” and how a single codebase, fanned out across dozens of publisher accounts, can quietly reach six figures of users before researchers connect the dots.

Timeline

  1. Socket's Threat Research Team discloses a family of 152 'live wallpaper' new-tab Chrome extensions built from a single codebase, spread across 38 publisher accounts and three brands, that harvest telemetry and fake Google organic search traffic.

Sources

  1. cybersecuritynews.comhttps://cybersecuritynews.com/chrome-extensions-hide-ad-tracking/
  2. gbhackers.comhttps://gbhackers.com/malicious-152-chrome-extensions-google-search/
  3. cyberpress.orghttps://cyberpress.org/chrome-extensions-manipulate-google-search/

Related incidents

Vulnerability exploitOngoing

CISA warns of actively exploited on-premises SharePoint Server flaws (CVE-2026-56164, CVE-2026-45659, CVE-2026-32201)

CISA issued an urgent hardening alert after confirming that attackers were chaining three vulnerabilities in on-premises Microsoft SharePoint Server β€” including an unauthenticated missing-authentication bug the U.S. National Vulnerability Database rates critical β€” to reach remote code execution, steal IIS machine keys and deploy malware.

Victim
Microsoft SharePoint Server
Zero-dayOngoing

SonicWall warns of two SMA 1000 zero-days exploited in the wild (CVE-2026-15409, CVE-2026-15410)

SonicWall issued an urgent advisory after attackers were caught chaining two zero-day flaws in its SMA 1000 secure remote-access appliances β€” an unauthenticated SSRF rated CVSS 10.0 and a post-authentication command-injection bug β€” with Rapid7 having observed the pair exploited in tandem against internet-facing devices before any patch existed.

Victim
SonicWall SMA 1000