Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
extension-plugin-hijackcredential-stealer-activitypersistence-methoddefense-evasion-method

Malicious Chrome Extensions Used for Data Theft and VKontakte Account Hijacking

Updated 3mo agoFirst seen Feb 16, 20262 sources

A malware campaign abused malicious Chrome extensions to compromise users and steal data, including a set of VKontakte-themed extensions that hijacked accounts at scale. Researchers reported that five related extensions (notably “VK Styles”, which reportedly reached ~400,000 installs before removal) were used to silently take over VKontakte accounts by subscribing victims to attacker-controlled groups, resetting settings on a recurring basis, and manipulating tokens to maintain persistence. The operation used a two-stage approach to evade detection: extensions fetched instructions/payload locations from a VKontakte profile’s HTML metadata and then executed attacker-controlled code retrieved from external infrastructure (including a GitHub account reportedly tied to the actor).

Separately, threat reporting highlighted a broader ecosystem issue in which 300+ malicious Chrome extensions with tens of millions of combined downloads were identified leaking or stealing user data, reinforcing the ongoing risk posed by browser extension supply-chain abuse. In contrast, Google also issued an urgent patch for an actively exploited Chrome zero-day, CVE-2026-2441 (use-after-free in CSS), but that vulnerability disclosure is a distinct event from the extension-based account takeover activity and should be tracked independently for patching and exposure management.

Share:
Malicious Chrome Extensions Used for Data Theft and VKontakte Account Hijacking
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 13, 20265mo ago

Researchers disclose campaign affecting over 500,000 users

Koi researchers reported that at least five infected Chrome extensions were used to hijack VK accounts, inject code into VK pages, manipulate cookies and security tokens, auto-join users to attacker-controlled groups, and maintain persistence by resetting settings every 30 days.

Jan 31, 20265mo ago

VK Styles reaches about 400,000 installs

The primary malicious extension, VK Styles, accumulated roughly 400,000 installs before it was removed, contributing to total victim counts exceeding 500,000 across the related extensions.

Jun 1, 20251y ago

Attackers expand and refine multi-extension infrastructure

From June 2025 through January 2026, the operators continuously updated the campaign, using at least five related extensions that fetched instructions from an attacker-controlled VK profile and second-stage code from GitHub to evade review and detection.

Malicious VK-themed Chrome extension campaign begins

GitHub commit history cited by Koi researchers indicates the operation was active by June 2025, using Chrome extensions disguised as VK customization tools to target VKontakte users.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Threat actors
1 linked
Affected products
1 linked
Github
Organizations
7 linked
Koi SecurityLinkedinYandexXGitHubGoogleVKontakte
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.