Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Keyv npm package compromised in supply chain attack
August 4, 2026
Cybercriminals Exploit ChatGPT for Scam Operations, OpenAI Reports
August 4, 2026
Russian Hacker Sells Company Access, Spies on Ukrainian Military
August 4, 2026
Home/Threats/Fake Copyright Notices Steal Google Credentials via Chrome Web Store
Threats

Fake Copyright Notices Steal Google Credentials via Chrome Web Store

Key Takeaways A sophisticated phishing campaign is targeting Chrome extension developers with fake copyright infringement notices. The attackers aim to steal Google credentials by directing...

Marcus Rodriguez
Marcus Rodriguez
June 4, 2026 4 Min Read
52 0

Key Takeaways

  • A sophisticated phishing campaign is targeting Chrome extension developers with fake copyright infringement notices.
  • The attackers aim to steal Google credentials by directing developers to highly convincing counterfeit Chrome Web Store login pages.
  • Successful compromise could allow attackers to push malicious updates to popular extensions, impacting a wide user base.
  • The scam leverages urgency and personalized details to appear legitimate, making it challenging to detect.

Sophisticated Phishing Targets Chrome Extension Developers

A new, highly deceptive phishing operation is actively targeting developers of Chrome extensions. This campaign utilizes meticulously crafted fake copyright removal notices that closely mimic official communications from the Chrome Web Store. The primary objective is to illicitly obtain Google credentials from unsuspecting developers.

Table Of Content

  • Key Takeaways
  • Sophisticated Phishing Targets Chrome Extension Developers
  • Anatomy of the Attack
  • What You Should Do

Detailed analysis of this threat, including a comprehensive report by Malwarebytes analysts, reveals the advanced nature of the scam. Developers are lured into entering their Google login information onto a counterfeit sign-in page, which poses a significant risk not only to their personal accounts but also to the millions of users who rely on their browser extensions. Given the widespread use of browser extensions in daily internet activities, such targeted attacks present a growing and critical security challenge.

Anatomy of the Attack

The phishing scheme begins with developers receiving an urgent notification, falsely claiming their extension is slated for removal due to copyright infringement. The message deliberately imposes a strict 48-hour deadline for an appeal, creating intense pressure for the victim to respond quickly and without thorough scrutiny.

The fraudulent appeal page is designed with extreme attention to detail, mirroring Google’s authentic communication style. It includes convincing elements such as a fabricated complaint number, a dynamic countdown timer, and a visual layout that faithfully replicates Google’s official branding. This level of sophistication is intended to trick even technically proficient developers, as highlighted in the Malwarebytes report shared with Cyber Security News (CSN).

The fake page is hosted on the domain dmca-chrome-extensions[.]click, which bears no affiliation with Google. Despite this, it presents itself as a “Chrome Web Store Developer Policy Center,” leveraging genuine Google branding to enhance its perceived legitimacy.

When a developer enters their extension ID into the deceptive page, the site dynamically retrieves public information related to that extension, including its real name, icon, and direct link to its Chrome Web Store listing. While this information is publicly accessible, its personalized presentation within the context of a fake complaint significantly enhances the illusion of authenticity. The scam integrates these legitimate details with a fabricated complaint number, a “date received,” and a real-time countdown, further escalating the sense of urgency and credibility.

A crucial component of the attack is the fake Google sign-in window that appears after a developer clicks “Continue to verification.” This window is remarkably convincing, displaying a padlock icon, a title bar, and an address that reads “accounts.google.com.” However, this is merely a graphical overlay embedded within the phishing page itself. The attackers have even customized its appearance to match the operating system (Mac or Windows) of the victim’s device, making it feel even more familiar and trustworthy.

A simple test can expose this deception: attempting to drag the fake sign-in window beyond the browser’s edge. A genuine system window would move freely, whereas this embedded graphic will stop at the browser’s boundary and disappear if the browser is minimized, revealing its true nature as an element within the page.

What You Should Do

  • Verify All Communications: Never trust warning emails that demand immediate action. Always navigate directly to your Chrome Web Store developer dashboard to check for official notifications about your extensions. Authentic policy notices will always appear within your official dashboard, not on external websites.
  • Be Wary of Urgency: Treat any message that employs countdown timers or strict deadlines to compel rapid action with extreme skepticism. Legitimate policy review processes typically do not impose such immediate pressure.
  • Inspect the URL Bar: Before entering any login credentials, meticulously examine your browser’s address bar. Ensure the domain is genuinely accounts.google.com and not a deceptive look-alike, such as dmca-chrome-extensions[.]click.
  • Enable Two-Step Verification (2SV): Implement strong two-step verification using a passkey or a hardware security key. This provides a critical layer of defense, as a stolen password alone would be insufficient for an attacker to gain access to your account.
  • Post-Compromise Actions: If you suspect you have entered your credentials on a phishing page, immediately change your Google password. Log out of all active sessions across all devices and thoroughly review your Chrome Web Store listings for any unauthorized updates or new versions that you did not publish.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain dmca-chrome-extensions[.]click Fake Chrome Web Store phishing page used to harvest Google developer credentials

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Acer Patches Critical Wave 7 Router Vulnerability CVE-2023-XXXX

Next Post

CISA Warns of Android Framework Integer Overflow Vulnerability Exploited in Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Flaws in Google Cloud AI Let Attackers Hijack CI/CD Pipelines
August 4, 2026
BINDCLOAK Malware Exploits Windows to Elevate Privileges, Steal Tokens
August 4, 2026
Fake AI Tools Deliver Malware to Developers, Granting Enterprise Access
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us