{"id":9973,"date":"2026-01-19T10:03:36","date_gmt":"2026-01-19T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/19\/17-new-malicious-chrome-ghostposter-extensions-with-840000-installs-steals-user-data\/"},"modified":"2026-01-19T10:03:36","modified_gmt":"2026-01-19T10:03:36","slug":"17-new-malicious-chrome-ghostposter-extensions-with-840000-installs-steals-user-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/19\/17-new-malicious-chrome-ghostposter-extensions-with-840000-installs-steals-user-data\/","title":{"rendered":"17 New Malicious Chrome GhostPoster Extensions with 840,000+ Installs Steals User Data"},"content":{"rendered":"<p>    17 New Malicious Chrome GhostPoster Extensions with 840,000+ Installs Steals User Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybercriminals have distributed 17 malicious browser extensions across Chrome, Firefox, and Edge platforms, collectively downloading over 840,000 times and compromising user security for years. <\/p>\n<p>The GhostPoster campaign, which emerged as early as 2020, used deceptive extension names like \u201cGoogle Translate in Right Click,\u201d \u201cYoutube Download,\u201d and \u201cAds Block Ultimate\u201d to appear legitimate while quietly stealing sensitive user information. <\/p>\n<p>These extensions successfully bypassed <a href=\"https:\/\/cybersecuritynews.com\/opensource-cloud-security-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">security reviews<\/a> from major browser stores, remaining active for up to five years before being discovered. <\/p>\n<p>The sheer scale of installations demonstrates the effectiveness of this attack and the difficulty users face distinguishing trustworthy extensions from dangerous imposters.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi4R09ga7eonRbKkto8L8mIiE-ig5A7GyfhMCaf5G_wXFvQSAq-TcopU18ToGGpbtOlrnPqM7l7o3OEseCw5w1YplYhXq2HV8uUJEHXI-jFEbvWK7gFwwo8EQsl2_c1vMCahJBTz4I0TLwub3wW-quFgugkdaimx7BZxeDo-Sn0d3NJgJAgKun6iwV1EMY\/s16000\/GhostPoster%2520Upload%2520to%2520Browser%2520Extension%2520Stores%2520%28Source%2520-%2520LayerX%2520Security%29.webp?ssl=1\" alt=\"GhostPoster Upload to Browser Extension Stores (Source - LayerX Security)\"><figcaption class=\"wp-element-caption\">GhostPoster Upload to Browser Extension Stores (Source \u2013 LayerX Security)<\/figcaption><\/figure>\n<\/div>\n<p>The attack exploits a fundamental weakness in <a href=\"https:\/\/cybersecuritynews.com\/seraphic-security-unveils-browsertotal-free-ai-powered-browser-security-assessment-for-enterprises\/\" target=\"_blank\" rel=\"noreferrer noopener\">browser security<\/a>: users trust extensions that appear in official stores. <\/p>\n<p>The malicious extensions used steganography to hide malicious code inside PNG image files, a technique that conceals data in plain sight. <\/p>\n<p>Once installed, the extensions extract the hidden payload and establish communication with attacker-controlled servers to download additional malicious scripts. <\/p>\n<p>The malware then performs several harmful actions including hijacking affiliate links for financial gain, injecting scripts to track user behavior, manipulating HTTP headers to disable security protections, and stealing credentials and personal data. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj7CC9qYYdUgwTUw-y5J64OGxNEYHvVZo7h39vhI_Wlcjtmjc9HVNC8osCypm2zjzsz5yi-9z00DH3ALxdUYxArHccONwbe5jvhrJzDkCS0diKcoYRZuloDKFUu7UKZQppBXV6UBwTJ9_LUF1geZJhByecByWwL9ywHk4l_JExv5ZFOpdKUt7eZJpevzBs\/s16000\/Firefox%2520Extension%2520Available%2520for%2520Download%2520in%2520Store%2520%28Source%2520-%2520LayerX%2520Security%29.webp?ssl=1\" alt=\"Firefox Extension Available for Download in Store (Source - LayerX Security)\"><figcaption class=\"wp-element-caption\">Firefox Extension Available for Download in Store (Source \u2013 LayerX Security)<\/figcaption><\/figure>\n<\/div>\n<p>The sophistication of these tactics shows this is not opportunistic malware but rather a well-planned operation targeting financial gain and sustained access to user devices.<\/p>\n<p>LayerX Security analysts <a href=\"https:\/\/layerxsecurity.com\/blog\/browser-extensions-gone-rogue-the-full-scope-of-the-ghostposter-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the full scope of the campaign after Koi Security initially discovered one malicious Firefox extension. <\/p>\n<p>Their investigation uncovered the interconnected infrastructure linking all 17 extensions, revealing that these were not isolated incidents but part of a coordinated effort. <\/p>\n<h2 class=\"wp-block-heading\" id=\"h-techniques-used\"><strong>Techniques used<\/strong><\/h2>\n<p>The research exposed how the threat actor systematically expanded from Microsoft Edge to Firefox and then to Chrome, adapting their techniques to fit each platform\u2019s security requirements.<\/p>\n<p>The malware\u2019s sophisticated <a href=\"https:\/\/cybersecuritynews.com\/researchers-unveiled-a-new-mechanism\/\" target=\"_blank\" rel=\"noreferrer noopener\">infection mechanism<\/a> relies on delayed execution to evade detection. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiQ1-3TT1qHF84V-0hR5eNwY0Gm414KqL7AQHcFdai9WlrpmYFGtSEzLJs2YUDZr2zBp5uOzPgHVKJyqkMCzfnKvc6rOwuxDm6Vu3s4exCRZGeXKmuNnygCzLA7Tw7txdKUUd-flbRY_ZyWgFsnv2yfZdsWyuQ2bJCuE73xI3kevkxYgHek4YlxUZxCeHY\/s16000\/Decoded%2520.png%2520Payload%2520%28Source%2520-%2520LayerX%2520Security%29.webp?ssl=1\" alt=\"Decoded .png Payload (Source - LayerX Security)\"><figcaption class=\"wp-element-caption\">Decoded .png Payload (Source \u2013 LayerX Security)<\/figcaption><\/figure>\n<\/div>\n<p>When installed, the extension waits 48 hours or longer before activating, allowing it to slip past security scanning during initial review. <\/p>\n<p>More advanced variants wait up to five days before connecting to remote servers, creating a window where the malware operates while <a href=\"https:\/\/cybersecuritynews.com\/how-intrusion-detection-and-prevention-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">detection tools<\/a> remain inactive. <\/p>\n<p>The malicious code remains embedded inside the extension\u2019s background script and uses encrypted payloads that are decoded only at runtime, making static analysis nearly impossible and ensuring the threat remains hidden until fully activated on victim machines.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 93%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/17-new-malicious-chrome-ghostposter-extensions\/\">17 New Malicious Chrome GhostPoster Extensions with 840,000+ Installs Steals User Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/17-new-malicious-chrome-ghostposter-extensions\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>17 New Malicious Chrome GhostPoster Extensions with 840,000+ Installs Steals User Data Cybercriminals have distributed 17 malicious browser extensions across Chrome, Firefox, and Edge platforms, collectively downloading over 840,000 times and compromising user security for years. The GhostPoster campaign, which emerged as early as 2020, used deceptive extension names like \u201cGoogle Translate in Right Click,\u201d [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9973","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9973"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9973"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9973\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9973"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9973"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9973"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}