Malicious Chrome Extensions Caught Faking Google Search Traffic
Content Summary: Security researchers at Socket discovered 152 Chrome "live wallpaper" extensions operating as a coordinated fraud network. These extensions lied about collecting user data on the Chrome Web Store, secretly logged IP addresses and browsing behavior, and manufactured fake Google organic search traffic to inflate ad revenue. This article breaks down exactly what happened, how the deception worked at a technical level, who was behind it, and what you should do right now if you had any of these installed.
| Detail | Summary |
|---|---|
| Extensions Caught | 152 Chrome "live wallpaper" new-tab extensions |
| Publisher Accounts | 38 separate Chrome Web Store accounts |
| Brand Backends | tabplugins[.].com, yowgames[.].com, chromewallpaper[.].com |
| Affected Users | ~105,000 (likely higher Chrome rounds install numbers) |
| Data Collected | IP address, ISP, browser type, timestamps, click counts, device info |
| Data Shared With | Google AdSense, DoubleClick, unnamed third-party ad partners |
| Fraud Method | Forged Google organic search attribution via UTM tags and signed redirect tokens |
| Anti-Forensic Behavior | IndexedDB wipe on every service worker start |
| Discovered By | Socket Threat Research Team (June 2025) |
| Status | Network dismantled after disclosure |
An Extension You Trusted Was Working Against You
Picture this. You install a wallpaper extension for Chrome because you want a nice anime or football-themed new tab page. It looks clean. It has decent ratings. The Chrome Web Store says right there under Privacy Practices: "This extension does not collect or use your data."
You believe it. Why wouldn't you?
What you did not know is that in the background, from the very first second it was installed, that extension was logging your IP address, your internet service provider, your browser configuration, what pages you had been on, how many times you clicked on things, and detailed information about your device and installed software. All of that was being quietly shipped off to ad networks and unnamed third parties.
How Socket Found It
Socket's Threat Research Team, the same group that regularly digs into supply chain threats inside open-source software and browser extensions, noticed something familiar about a cluster of Chrome extensions in 2025. They all looked different on the surface. Different publisher names. Different wallpaper themes. Anime, cars, football, games.
But underneath, every extension in the family shared a single codebase and pointed back to three brand backends: tabplugins[.].com, yowgames[.].com, and chromewallpaper[.].com.
The operation spanned 38 separate Chrome Web Store publisher accounts and had accumulated approximately 105,000 installs from unsuspecting users. That 105,000 figure is almost certainly a floor, not a ceiling, because Chrome rounds its install counts into buckets.
The Privacy Lie That Made It All Possible
The first and most straightforward piece of the deception was a simple lie.
On the Chrome Web Store listing for every one of these 152 extensions, the Privacy Practices tab stated clearly that the extension does not collect or use user data, does not sell data, and does not transfer data for purposes unrelated to the extension's core function.
That is exactly what users saw when they decided to install.
The linked privacy policy told a completely different story. The operator's own privacy policy directly contradicted this, admitting the extensions log IP addresses, ISP, click counts, and referrer data and sharing it with Google AdSense, DoubleClick, and unnamed third-party ad partners.
How They Turned Extension Traffic Into Fake Google Search Visits
This is where the operation gets genuinely clever and genuinely damaging.
A subset of 54 extensions built on the tabplugins template did something more sophisticated than just collect data. They manufactured fake organic search traffic and fed it into Google Analytics and ad measurement platforms as if it were real.
**On install:**The moment you finished installing one of these extensions, the background service worker automatically opened a new browser tab to tabplugins.com. That tab URL included the parameters utm_source=google&utm_medium=organic.
On uninstall: This is where it got technically sophisticated. When you removed the extension, it fired one final network request using Chrome's setUninstallURL function. That request was not to tabplugins.com directly. It used a google.com/url wrapper that reproduced Google's signed VED and USG redirect tokens, making the outbound ping appear to analytics as a human clicking a legitimate Google search result.
The Anti-Forensic Routine That Reveals Something Darker
Every single extension in this family of 152 shipped with an identical routine buried in the background service worker. Every time the service worker started up, it called indexedDB.databases() and then ran a loop that deleted every IndexedDB database it could find within scope.
The Network Was Built to Survive Takedowns
One of the more professionally designed aspects of this campaign was its resilience to removal.
What the Indicators of Compromise Tell Security Teams
Socket's analysis produced a clean set of indicators that security and operations teams can use to detect this campaign across their environments.
| IOC Type | Value | Significance |
|---|---|---|
| Domain | tabplugins[.].com | Primary brand backend; source of forged Google attribution |
| Domain | yowgames[.].com | Second brand backend; undisclosed telemetry routing |
| Domain | chromewallpaper[.].com | Third brand; HTTP 301 redirect to owhit[.].com |
| Domain | owhit[.].com | Final destination; AdSense-monetized landing page |
| IP Address | 147[.].79[.].120[.].202 | tabplugins[.].com origin server on Hostinger |
| IP Address | 92[.].112[.].198[.].22 | Secondary tabplugins[.].com server on Hostinger |
| URL Pattern | utm_source=google&utm_medium=organic | Forged organic attribution in install ping |
| URL Pattern | google.com/url?...ved=...usg=... pointing to tabplugins.com |
Cloaked uninstall redirect mimicking real search click |
| Code Pattern | indexedDB.databases() loop with deleteDatabase() | Anti-forensic state wipe on every service worker start |
| Code Pattern | setUninstallURL with google.com/url wrapper | Forged uninstall attribution ping |
Why Chrome's Review Process Did Not Catch This
This question matters more than it might seem at first, because 152 extensions across 38 accounts is not a small slip through the cracks. That is a sustained operation.
What You Should Do Right Now
If you use Chrome and you have installed any wallpaper or new-tab extension in the past year, here are concrete steps to take today.
Check your installed extensions. Open Chrome and go to chrome://extensions. Look at everything you have installed. If you see any extension you don't regularly use or that you don't remember installing, remove it.
Cross-reference the brand domains. If any extension you have installed was published by an account associated with tabplugins.com, yowgames.com, or chromewallpaper.com (which redirects to owhit.com), remove it immediately.
Verify your default search engine. Go to Chrome Settings and check that your default search engine has not been changed.
Read privacy policies before installing extensions. Not the Chrome Web Store disclosure tab, but the actual linked privacy policy. If they contradict each other, that is a serious red flag.