← VK (VKontakte)

2026 Malicious Chrome extensions — 500k accounts hijacked

2026 500.0K records affected Share on X

Data compromised

Account access, subscription to attacker groups, account settings manipulation

Technical writeup

Malware campaign hijacked over 500,000 VKontakte accounts through malicious Chrome extensions masquerading as VK customization tools. 'VK Styles' had ~400,000 installations. Extensions used multi-stage code injection, auto-subscribed users to attacker-controlled groups, reset account settings, manipulated CSRF tokens. Main extension removed from Chrome Web Store February 6, 2026.

Root cause

Malicious Chrome extensions; account hijacking via browser extension compromise.

References