Cybercriminals have launched a massive new adware campaign that has successfully compromised approximately 30,000 users.
Threat actors are utilizing the official Google Chrome Web Store to distribute over 50 malicious browser extensions.
To trick unsuspecting victims into downloading their payload, the attackers cleverly disguised these malicious tools as attractive live wallpapers.
Once a user installs the extension, the software initiates a chain of unauthorized activities designed to hijack browser sessions, inject unwanted advertisements, and track user behavior across the web.
This large-scale campaign highlights the ongoing struggle to secure official extension repositories against sophisticated abuse tactics.
Adware is no longer just a minor annoyance; it is a highly profitable enterprise for cybercriminals who monetize hijacked web traffic and stolen browsing data.
By distributing the risk across multiple files and accounts, the operators ensure their campaign survives even if a few of their extensions are flagged and removed by security researchers.

Fake Wallpaper Extensions Hit Users
The attackers strategically deployed these malicious extensions across three publisher accounts. This segmented approach prevents a single point of failure.
If Google security teams detect and ban one publisher account, the other two can continue operating without interruption.
The core malicious functionality of these fake live wallpapers relies heavily on fetching remote code after the initial download is complete.

Once a victim adds the extension to their browser, it immediately establishes a connection to an external command-and-control server.
The attackers are actively pushing remote HTML payloads to more than 40 of these extensions.
By dynamically loading their malicious code from an external source rather than including it in the initial installation package, the developers successfully bypass the static security checks performed by the Chrome Web Store during the review process.
A highly notable technical aspect of this specific campaign is the deliberate manipulation of local browser storage.
The extensions are explicitly programmed to wipe the IndexedDB database upon initial installation and during every subsequent browser startup.

Dealing with sophisticated browser-based adware requires immediate action from both individual users and enterprise security teams.
The remote HTML execution capability means these extensions could potentially be updated to deliver more severe malware payloads in the future, elevating this from a basic nuisance to a significant security risk, Unit42 said.
Moving forward, users must remain highly vigilant when downloading browser enhancements.
Always check developer reviews, verify the publisher’s history, and question why a simple cosmetic extension like a wallpaper might require extensive permissions to read and change website data.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.