A new cybersecurity investigation has uncovered a vast network of Google Chrome extensions that appear to be innocent wallpaper extensions, but in reality appear to serve a very different purpose. According to findings by Socket researchers , a total of 152 Chrome extensions are linked to an organized potentially unwanted software (PUP) distribution operation that relies on user tracking and web traffic manipulation techniques.

The scale of the campaign is considered particularly significant, as the specific extensions have recorded more than 105,000 installations, while being associated with dozens of different publisher accounts in the Chrome Web Store. The case highlights once again the difficulties users face in assessing the reliability of browser extensions, even when they are hosted on official distribution platforms.
A complex ecosystem of extensions
Researchers identified that the network spans 38 different publisher accounts and relies on three main backend infrastructures, which act as central data management and collection.
See also: Google Chrome update fixes 28 vulnerabilities
Most of the extensions are presented as tools that offer live wallpapers, anime backgrounds, gaming themes or custom new tabs. This is a category of applications that has traditionally attracted great interest from users, especially among young people and fans of pop culture.
Some of these extensions are:
- Neymar – Football Live Wallpaper (laafpeklcnlfmjaofbndehkjpnccbhek)
- Satoru Gojo Manga Live Wallpaper (mnpacdigbockiilmilhbedciadenfdnb)
- Porsche 911 – Sports Car Live Wallpaper (dead service worker) (iedplnnolciaofkakkjmcojnmklpfikg)
- Satoru Gojo Live Wallpaper (ipiabbhcinknabpoihaakdahgghllelpj)
- Hello Kitty Wallpapers HD New Tab (hijpkhinofkdobfagfbobnnoihmopgkk)
- Pusheen Cat Wallpapers HD New Tab (famchdjojcnakamhkddkpaglnkonkfnl)
- Peach & Goma Wallpapers HD New Tab (nomekamioepglinefhenifnbegjhfiai)
- Spider-Man Miles Morales Swing Live Wallpaper (jjngbcodoldjmpjpfbhfelaljbdlkekh)
- BMW M3 Neon Night Drive Live Wallpaper (gfikbhpfjldbbikolkcimfgmejhdkjbe)
- BMW Wallpapers (dbiamdajndfmpmmeklcbbnekhkdcakhf)
- Death Note Anime Wallpapers HD New Tab (pkdloppfapenphihgbldhjjlfhgnkmcg)
- Sonic Frontiers Starfall Live Wallpaper (imkepemaflommlonnppjobgdpokbfmoj)
- Tanjiro – Demon Slayer Live Wallpaper (ibglidkppckhminbhbgcajomjplomcka)
- Neymar New Tab Wallpaper (gkbfokaephnaajnmpgiieidpfieamggb)
- Anime Car Drift Live Wallpaper (bcafgkhoifffmnoajkgmbhcojpabjffm)
- Choso Wallpapers New Tab (ojeaociifmdciibodcifjjocdlbjjeep)
- Anime Rain Live Wallpaper (npcghghfkbpgiamoifabankdnmopenni)
- Minecraft Sakura Pond Live Wallpaper (mjdhgndjbajnanfimjipafechjbakdhh)
- Straw Hat Live Wallpaper Ghost of Tsushima (lblgjffllphdepifdkfhlihddckhlkll)
- Zenitsu Agatsuma Live Wallpaper (laeciedchhnmnfhllplcgkfcdbdfgdhn)
However, behind the attractive environment lies a mechanism that appears to collect information and create artificial traffic signals to advertising networks and partner platforms.
What extensions claim and what they actually do
One of the most worrying elements of the research concerns the discrepancy between the statements displayed in the Chrome Web Store and the extensions' actual privacy policies.
In most cases, the listings state that no personal user data is collected or used. However, the respective privacy policies reveal that data such as:
- IP addresses
- Internet Service Provider (ISP) information
- Click and interaction data
- Traffic referral sources
- Usage statistics
According to the researchers, some of this data is shared with advertising ecosystems such as Google AdSense, DoubleClick , and other advertising partners.
This particular practice raises serious questions about transparency and compliance with modern data.
The "fake organic traffic" technique
The most interesting finding of the research concerns the way in which extensions attempt to construct artificial signals of organic traffic.
Some of them include special JavaScript that is triggered during installation or uninstallation. The code automatically opens specific URLs, which contain UTM parameters that are commonly used to track advertising campaigns.
This creates the illusion that a user visited a website through an organic Google search, when in fact the visit was automatically triggered by the extension itself.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Experts characterize this technique as a form of fraudulent attribution, i.e. falsifying the origin of traffic with the aim of altering analytical data and possibly increasing advertising revenue.
See also: CISA: Cisco, Chrome and Arista vulnerabilities in the KEV List

From adware to traffic attribution fraud
Socket assesses the campaign as a financially motivated enterprise that combines features of adware, user tracking, and performance advertising fraud.
The perpetrators appear to be trying to exploit traffic measurement systems by creating false interaction signals, which may affect the evaluation of websites, advertising campaigns, or affiliate programs.
Although no direct capabilities for remote execution of malicious code have been identified, the ability to track users and manipulate data is considered particularly problematic.
The invisible function that troubles researchers
Another finding that caused concern concerns the existence of code capable of detecting and deleting IndexedDB databases when a service worker is started.
Although the feature appears to be inactive for now, its presence raises questions about its true purpose. The researchers note that such capabilities could theoretically be used to modify stored data or delete information related to other applications.
The existence of dormant code is often an indication that the creators retain the ability to enable additional features in the future.
See also: Chrome emergency update: 5th zero-day in 2026

Who is behind the network?
The exact identity of those responsible remains unknown. However, analysts have identified several indirect indications that point to a possible connection to Turkey.
Although there is no evidence that allows for a secure attribution of responsibility, the geographical origin of the infrastructure, certain linguistic elements, and the technical details of the backend services seem to converge in this direction.
The case is yet another reminder that even the simplest and most popular browser extensions can be turned into tools for data collection and manipulation of online activity. For users, carefully evaluating the permissions an extension requests and regularly reviewing installed add-ons remain key protection measures against increasingly sophisticated digital threats.
