{"id":13608,"date":"2026-06-14T10:03:52","date_gmt":"2026-06-14T10:03:52","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/14\/152-chrome-extensions-hide-ad-tracking-and-fake-google-search-traffic\/"},"modified":"2026-06-14T10:03:52","modified_gmt":"2026-06-14T10:03:52","slug":"152-chrome-extensions-hide-ad-tracking-and-fake-google-search-traffic","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/14\/152-chrome-extensions-hide-ad-tracking-and-fake-google-search-traffic\/","title":{"rendered":"152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic"},"content":{"rendered":"<p>    152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">152 Chrome \u201clive wallpaper\u201d <a href=\"https:\/\/cybersecuritynews.com\/131-malicious-extensions-targeting-whatsapp\/\" target=\"_blank\" rel=\"noreferrer noopener\">extensions on the Chrome Web Store<\/a> have been caught secretly logging user data and faking Google \u201corganic search\u201d traffic to inflate ad revenue, despite promising they do not collect any data.<\/p>\n<p class=\"wp-block-paragraph\">This adware\u2011adjacent campaign abuses new\u2011tab extensions to launder extension\u2011generated visits into what appears to be legitimate search traffic, polluting analytics for advertisers and Google alike.<\/p>\n<p class=\"wp-block-paragraph\">Socket\u2019s Threat Research Team uncovered a coordinated family of 152 new\u2011tab \u201clive wallpaper\u201d Chrome extensions built from a single codebase but spread across 38 publisher accounts and three brands: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com (which redirects to owhit[.]com).<\/p>\n<p class=\"wp-block-paragraph\">The extensions use popular themes such as anime, games, football, and car wallpapers to attract installs, and together they report around 105,000 users. However, Chrome\u2019s rounded install buckets make this only a lower\u2011bound estimate.<\/p>\n<p class=\"wp-block-paragraph\">On their Chrome Web Store \u201cPrivacy practices\u201d tab, the listings state that the extensions do not collect or use user data, do not sell data, and do not transfer data for unrelated purposes.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi6KqwEHQ9mV2jZiYSooMWffaWVFb9eOeqdltOWJRtiIDVqhM8Q5n_M8uurwSzbmmGnddSXaY6hWEM6Q5MaP_grb646icm77zyCyt1gdiiXpI9agXllcvvh4UoZ_fqsnGjSvayLTCNAQnFJTcE8v9wXgeqL16Jv1SgQWv4iDAdBIlh8wPxemYfIG4OssXw\/s1600\/Screenshot%25202026-06-13%2520105748%2520%25281%2529.webp?ssl=1\" alt=\"The False Privacy Disclosure (Source : Socket )\"><figcaption class=\"wp-element-caption\">The False Privacy Disclosure (Source : Socket )<\/figcaption><\/figure>\n<h2 id=\"h-chrome-extensions-hide-tracking-and-fake-traffic\" class=\"wp-block-heading\"><strong>Chrome Extensions Hide Tracking and Fake Traffic<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">However, the linked privacy policy clearly states that it logs IP addresses, browser type, ISP, timestamps, referring pages, click counts, and details about the user\u2019s device and installed software, which are shared with Google AdSense, <a href=\"https:\/\/cybersecuritynews.com\/malspam-attack-uses-google-doubleclick-redirects\/\" target=\"_blank\" rel=\"noreferrer noopener\">DoubleClick<\/a>, Google Analytics, and unnamed third\u2011party ad partners.<\/p>\n<p class=\"wp-block-paragraph\">A 54\u2011extension subset built on the newer tabplugins template takes this further by forging Google organic\u2011search attribution.<\/p>\n<p class=\"wp-block-paragraph\">On install, the background service worker automatically opens a tab to tabplugins[.]com with\u00a0utm_source=google&amp;utm_medium=organic, causing analytics to record the visit as if the user discovered the site via a normal Google search result instead of an extension\u2011forced navigation.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgJnvCjCZ76bmOQGwasF5abU0Rs6XD4fp9OEMtB0OxOIPROzvZsR6BMuA_9GdTBYFzG9pBX_hfZRFfziu2EKE1Wl1a1BMm17L_sf8e8QcfEhRDHz4FHAtZxUcOmccU10ws3CdP0iTT1UTw-f3g71uBUAosdXPceDnOVE4NTd6-lpN-eV74I76Tezg8UPbA\/s1600\/Screenshot%25202026-06-13%2520105808%2520%25281%2529.webp?ssl=1\" alt=\"\nThe network uses 38 publisher accounts across three domains and two hosting clusters, each tied to separate Google Ad Manager or AdSense accounts(source : socket)\"><figcaption class=\"wp-element-caption\">The network uses 38 publisher accounts across three domains and two hosting clusters, each tied to separate Google Ad Manager or AdSense accounts(source : socket)<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">On uninstall, the extension fires a crafted\u00a0https:\/\/www.google.com\/url?\u2026&amp;url=https:\/\/tabplugins.com\/\u2026&amp;ved=\u2026&amp;usg=\u2026\u00a0redirect, mimicking the exact format and signed tokens Google uses for real search\u2011result clicks, so the uninstall ping is indistinguishable from a human clicking a Google result.<\/p>\n<p class=\"wp-block-paragraph\">This allows the operator to present extension\u2011generated traffic as high\u2011value \u201corganic search\u201d visits, inflating perceived popularity and trustworthiness to advertisers and affiliate programs.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEigB7pbfPH_mUPNRU-BSyJgWBDOJZ_POMUBSDJyhZ__bsyu-BvLPuz7STIrdw6-WVOJNRG9lr1TI9rmrMVgd5Sm9SVw6m5KDCJ8P8z5lNxWKFhhKbCQ8RT4jKLtL9w33Nb74QjfP4zSC5fGVtuIOzkjx9tB_NYLKnbPFh3erpgTMkefkmlzmpGzlD0rQbM\/s1600\/Screenshot%25202026-06-13%2520110029%2520%25281%2529.webp?ssl=1\" alt=\"The privacy policy admits collecting IP, ISP, and click data for Google AdSense, contradicting its Chrome Web Store disclosure (source :socket )\"><figcaption class=\"wp-element-caption\">The privacy policy admits collecting IP, ISP, and click data for Google AdSense, contradicting its Chrome Web Store disclosure (source :socket )<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Every analyzed family member also exhibits undisclosed anti\u2011forensic behavior. On each service\u2011worker start, the background script enumerates and deletes every IndexedDB database accessible to the extension\u2019s own origin.<\/p>\n<p class=\"wp-block-paragraph\">In this build, the extension stores its settings in localStorage. It does not use IndexedDB, so the wipe currently destroys nothing.<\/p>\n<p class=\"wp-block-paragraph\">However, it remains a strong fingerprint and demonstrates a built\u2011in capability to reset any future IndexedDB\u2011based telemetry within the extension silently.<\/p>\n<p class=\"wp-block-paragraph\">The same\u00a0Deleted IndexedDB database:\u00a0log string, install\u2011navigation behavior, and\u00a0setUninstallURL\u00a0pattern appear across 141 retrievable service\u2011worker scripts tied to 152 total extension IDs, with 11 already delisted.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/socket.dev\/blog\/152-chrome-live-wallpaper-extensions-hid-ad-tracking\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to Socket Research<\/a>, some variants even include a syntactically broken <code>bg.js<\/code> file that prevents the background logic from executing, suggesting rushed mass production of the extensions despite successfully passing store review.<\/p>\n<p class=\"wp-block-paragraph\">The extensions do not inject ads into arbitrary websites. Instead, they redirect users to operator-controlled domains that are heavily monetized through programmatic advertising.<\/p>\n<p class=\"wp-block-paragraph\">One such domain, <code>tabplugins[.]com<\/code>, operates a <a href=\"https:\/\/cybersecuritynews.com\/wordpress-ad-fraud-plugins\/\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress-based extension<\/a> catalog integrated with a Prebid header-bidding stack from Advergic (<code>avads[.]live<\/code>).<\/p>\n<p class=\"wp-block-paragraph\">Feeding ad exchanges including Google Ad Manager, Xandr\/AppNexus, PixFuture, and SmileWanted, while using Google Analytics 4 and FOU Analytics for user tracking.<\/p>\n<p class=\"wp-block-paragraph\">Archived snapshots of yowgames[.]com and owhit[.]com shows direct <a href=\"https:\/\/cybersecuritynews.com\/poisoned-google-ads\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google AdSense<\/a> and Analytics integrations with their own publisher IDs and GA4 properties, reusing boilerplate privacy language about DoubleClick and third\u2011party advertisers.<\/p>\n<p class=\"wp-block-paragraph\">The result is a financially motivated traffic\u2011fraud operation that turns silent new\u2011tab installs into what appear to be genuine Google search visits, at the expense of user privacy and measurement integrity.<\/p>\n<p class=\"wp-block-paragraph\">For users, the main risk is enrollment in deceptive traffic measurement and undisclosed telemetry, not device\u2011level compromise.<\/p>\n<p class=\"wp-block-paragraph\">Security teams should hunt for a shared fingerprint: an MV3 extension with a background worker that logs the deleted IndexedDB database, runs an <code>indexedDB.databases().then(... deleteDatabase ...)<\/code> loop, and opens <code>utm_source=google&amp;utm_medium=organic<\/code> tabs on install.<\/p>\n<p class=\"wp-block-paragraph\">Additional indicators include an uninstall URL pointing to a <code>google.com\/url<\/code> wrapper that redirects to <code>tabplugins[.]com<\/code>, <code>yowgames[.]com<\/code>, <code>chromewallpaper[.]com<\/code>, or <code>owhit[.]com<\/code>.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chrome-extensions-hide-ad-tracking\/\">152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chrome-extensions-hide-ad-tracking\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic 152 Chrome \u201clive wallpaper\u201d extensions on the Chrome Web Store have been caught secretly logging user data and faking Google \u201corganic search\u201d traffic to inflate ad revenue, despite promising they do not collect any data. This adware\u2011adjacent campaign abuses new\u2011tab extensions to launder extension\u2011generated [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[768,129,63],"tags":[130],"class_list":["post-13608","post","type-post","status-publish","format-standard","hentry","category-chrome","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13608"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13608"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13608\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13608"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13608"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}