Malicious Chrome Extensions Caught Faking Google Search Traffic

Content Summary: Security researchers at Socket discovered 152 Chrome "live wallpaper" extensions operating as a coordinated fraud network. These extensions lied about collecting user data on the Chrome Web Store, secretly logged IP addresses and browsing behavior, and manufactured fake Google organic search traffic to inflate ad revenue. This article breaks down exactly what happened, how the deception worked at a technical level, who was behind it, and what you should do right now if you had any of these installed.

Detail Summary
Extensions Caught 152 Chrome "live wallpaper" new-tab extensions
Publisher Accounts 38 separate Chrome Web Store accounts
Brand Backends tabplugins[.].com, yowgames[.].com, chromewallpaper[.].com
Affected Users ~105,000 (likely higher  Chrome rounds install numbers)
Data Collected IP address, ISP, browser type, timestamps, click counts,
device info
Data Shared With Google AdSense, DoubleClick, unnamed third-party ad
partners
Fraud Method Forged Google organic search attribution via UTM tags and
signed redirect tokens
Anti-Forensic Behavior IndexedDB wipe on every service worker start
Discovered By Socket Threat Research Team (June 2025)
Status Network dismantled after disclosure

An Extension You Trusted Was Working Against You

Picture this. You install a wallpaper extension for Chrome because you want a nice anime or football-themed new tab page. It looks clean. It has decent ratings. The Chrome Web Store says right there under Privacy Practices: "This extension does not collect or use your data."

You believe it. Why wouldn't you?

What you did not know is that in the background, from the very first second it was installed, that extension was logging your IP address, your internet service provider, your browser configuration, what pages you had been on, how many times you clicked on things, and detailed information about your device and installed software. All of that was being quietly shipped off to ad networks and unnamed third parties.

How Socket Found It

Socket's Threat Research Team, the same group that regularly digs into supply chain threats inside open-source software and browser extensions, noticed something familiar about a cluster of Chrome extensions in 2025. They all looked different on the surface. Different publisher names. Different wallpaper themes. Anime, cars, football, games.

But underneath, every extension in the family shared a single codebase and pointed back to three brand backends: tabplugins[.].com, yowgames[.].com, and chromewallpaper[.].com.

The operation spanned 38 separate Chrome Web Store publisher accounts and had accumulated approximately 105,000 installs from unsuspecting users. That 105,000 figure is almost certainly a floor, not a ceiling, because Chrome rounds its install counts into buckets.

The Privacy Lie That Made It All Possible

The first and most straightforward piece of the deception was a simple lie.

On the Chrome Web Store listing for every one of these 152 extensions, the Privacy Practices tab stated clearly that the extension does not collect or use user data, does not sell data, and does not transfer data for purposes unrelated to the extension's core function.

That is exactly what users saw when they decided to install.

The linked privacy policy told a completely different story. The operator's own privacy policy directly contradicted this, admitting the extensions log IP addresses, ISP, click counts, and referrer data and sharing it with Google AdSense, DoubleClick, and unnamed third-party ad partners.

How They Turned Extension Traffic Into Fake Google Search Visits

This is where the operation gets genuinely clever and genuinely damaging.

A subset of 54 extensions built on the tabplugins template did something more sophisticated than just collect data. They manufactured fake organic search traffic and fed it into Google Analytics and ad measurement platforms as if it were real.

**On install:**The moment you finished installing one of these extensions, the background service worker automatically opened a new browser tab to tabplugins.com. That tab URL included the parameters utm_source=google&utm_medium=organic.

On uninstall: This is where it got technically sophisticated. When you removed the extension, it fired one final network request using Chrome's setUninstallURL function. That request was not to tabplugins.com directly. It used a google.com/url wrapper that reproduced Google's signed VED and USG redirect tokens, making the outbound ping appear to analytics as a human clicking a legitimate Google search result.

The Anti-Forensic Routine That Reveals Something Darker

Every single extension in this family of 152 shipped with an identical routine buried in the background service worker. Every time the service worker started up, it called indexedDB.databases() and then ran a loop that deleted every IndexedDB database it could find within scope.

The Network Was Built to Survive Takedowns

One of the more professionally designed aspects of this campaign was its resilience to removal.

What the Indicators of Compromise Tell Security Teams

Socket's analysis produced a clean set of indicators that security and operations teams can use to detect this campaign across their environments.

IOC Type Value Significance
Domain tabplugins[.].com Primary brand backend; source of forged Google attribution
Domain yowgames[.].com Second brand backend; undisclosed telemetry routing
Domain chromewallpaper[.].com Third brand; HTTP 301 redirect to owhit[.].com
Domain owhit[.].com Final destination; AdSense-monetized landing page
IP Address 147[.].79[.].120[.].202 tabplugins[.].com origin server on Hostinger
IP Address 92[.].112[.].198[.].22 Secondary tabplugins[.].com server on Hostinger
URL Pattern utm_source=google&utm_medium=organic Forged organic attribution in install ping
URL Pattern google.com/url?...ved=...usg=... pointing to
tabplugins.com
Cloaked uninstall redirect mimicking real search click
Code Pattern indexedDB.databases() loop with deleteDatabase() Anti-forensic state wipe on every service worker start
Code Pattern setUninstallURL with google.com/url wrapper Forged uninstall attribution ping

Why Chrome's Review Process Did Not Catch This

This question matters more than it might seem at first, because 152 extensions across 38 accounts is not a small slip through the cracks. That is a sustained operation.

What You Should Do Right Now

If you use Chrome and you have installed any wallpaper or new-tab extension in the past year, here are concrete steps to take today.

Check your installed extensions. Open Chrome and go to chrome://extensions. Look at everything you have installed. If you see any extension you don't regularly use or that you don't remember installing, remove it.

Cross-reference the brand domains. If any extension you have installed was published by an account associated with tabplugins.com, yowgames.com, or chromewallpaper.com (which redirects to owhit.com), remove it immediately.

Verify your default search engine. Go to Chrome Settings and check that your default search engine has not been changed.

Read privacy policies before installing extensions. Not the Chrome Web Store disclosure tab, but the actual linked privacy policy. If they contradict each other, that is a serious red flag.