The modern web browser ecosystem remains a premier target for sophisticated traffic-manipulation campaigns that exploit the implicit trust users place in official software marketplaces. A comprehensive threat analysis recently exposed a highly coordinated, horizontally scaled network consisting of 152 Chrome Web Store extensions masquerading as “live wallpaper” customization utilities. Operating collectively across 38 distinct publisher accounts and anchoring to three main brand infrastructure backends (tabplugins.com, yowgames.com, and chromewallpaper.com), this campaign has successfully accrued over 105,000 installations. The core mechanism relies on an extreme disconnect between the extension’s regulatory disclosures and its actual run-time capabilities. While every single listing explicitly states on the Chrome Web Store dashboard that it does not collect or use consumer data, the operators’ linked legal privacy policies completely contradict this assertion, acknowledging the active logging of user IP addresses, Internet Service Providers (ISPs), interaction click counts, and referral structures to fuel programmatic revenue streams via platforms like Google AdSense, DoubleClick, and third-party advertising exchanges.
Horizontal Scaling and Mass-Production Infrastructure
To survive the automated compliance filters and manual curation checks deployed by extension marketplaces, the threat actors behind this operation abandoned traditional monolithic malware architectures in favor of a decentralized distribution strategy. By packaging an identical, highly standardized codebase into distinct programmatic variants and dispersing them across dozens of seemingly independent publisher handles—including accounts like ZainAhamed1994, gamingify009, deckapp.dev, wallpaperbg, and ExtNext—the campaign achieves substantial operational resilience. This defensive fracturing means that a single automated compliance take-down by security teams fails to paralyze the broader infrastructure, allowing parallel extensions to continue generating traffic unchecked. The underlying web backends further mirror this segmented architecture; while tabplugins.com serves as the primary nexus for a 54-listing subset using a modernized template, sister domains like yowgames.com and owhit.com (the target destination for chromewallpaper.com) act as independent monetized islands, isolating telemetry collection and ensuring that a domain block on one brand leaves the remaining digital real estate untouched.
Deceptive Attribution and Organic Traffic Forgery Mechanisms
The technical core of the newer 54-listing subset lies in its ability to manipulate digital marketing attribution metrics through systematic referral forgery. Within the background service worker architecture (js/bg.js), the extensions maintain hardcoded URLs designed to simulate legitimate human web navigation. Upon a fresh installation, the chrome.runtime.onInstalled listener initiates a new tab event pointing toward the operator’s brand page, embedded with tracking metrics explicitly declaring utm_source=google&utm_medium=organic. Far more manipulative, however, is the mechanism triggered during an uninstallation event. By utilizing the chrome.runtime.setUninstallURL API, the extension registers an outbound ping wrapped in an authentic google.com/url redirect path. This generated string contains pre-fabricated, signed ved and usg tokens—cryptographic identifiers typically generated exclusively by Google’s live search engine to track actual user interaction. When the browser hits this endpoint upon removal, it effectively launders the forced extension traffic, making the programmatic redirection appear to analytics platforms, ad exchanges, and downstream affiliate frameworks as a high-value, earned organic click originating straight from a human Google Search result.
Code-Level Behavior and Anti-Forensic Executions
A detailed static and dynamic binary analysis of the extension packages uncovers a curious and universal forensic footprint embedded into 100 percent of the discovered codebase. On every initial service-worker start-up, the file js/bg.js executes an automated routine utilizing the indexedDB.databases() promise chain to enumerate all client-side databases visible to the executing environment, subsequently executing an aggressive indexedDB.deleteDatabase() loop. Within the framework of Manifest V3 (MV3), an extension background service worker is sandboxed entirely to its own isolated origin (chrome-extension://<id>). Consequently, this anti-forensic purge remains inert regarding external website states, failing to modify target session cookies or third-party storage nodes; however, its universal implementation across the entire fleet serves as an unmistakable operational fingerprint. Additional indicators of rushed, automated assembly include broken image modes due to absent local assets, alongside a minor telemetry leak where the local DOM dynamically requests favicon elements from Google’s public s2/favicons API for every single custom user-saved shortcut, inadvertently exposing user browsing patterns to external logging servers.
Programmatic Ad Tech Integration and the Monetization Funnel
The ultimate objective of this sprawling horizontal architecture is the monetization of synthetic, falsely attributed traffic streams through advanced programmatic ad-tech stacks. The tabplugins.com infrastructure funnel redirects arriving victims to landing spaces that invoke a specific Prebid header-bidding wrapper (av-tabplugins.js) operated via the ad-tech vendor Advergic. This script actively hooks into major programmatic syndications—including Google Ad Manager networks 23301900962 and 23324153939, AppNexus/Xandr, PixFuture, and SmileWanted—triggering high-yield full-screen interstitial ad auctions alongside Google Analytics 4 tracking scripts. In parallel, the yowgames.com and owhit.com nodes bypass header-bidding intermediaries to serve direct Google AdSense programmatic banners via individual publisher profiles ca-pub-2685573472598175 and ca-pub-6596604135510481. By combining falsified search metrics with legitimate programmatic ad auctions, the operators extract top-tier advertising payouts from ad networks that believe they are serving impressions to deeply engaged, organically sourced human audiences.
Threat Mapping via the MITRE ATT&CK Framework
To systematically contextualize the operational behavior of this adware network, security teams can map its actions directly onto standard threat frameworks. The primary access and execution vector relies heavily on T1176.001 (Browser Extensions), establishing a persistent, silent foothold within the user’s everyday workspace. The masquerading of the uninstall redirects as official search paths leverages T1036 (Masquerading), effectively hiding malicious activity behind trusted Google domain headers. The persistent execution of the IndexedDB clearing routine highlights an explicit attempt at T1070 (Indicator Removal), seeking to reset the extension environment to dodge baseline local detection tools. Communication with the multi-brand command infrastructure relies on standard web architectures categorized under T1071.001 (Application Layer Protocol: Web Protocols). Finally, the orchestration of 38 distinct publisher profiles and multiple secondary domains demonstrates advanced execution of T1583.001 (Acquire Infrastructure: Domains), showing a highly calculated approach to programmatic infrastructure acquisition designed for maximum lifetime resilience.
Our Opinion on This Case
From a cybersecurity engineering and platform architecture standpoint, this 152-extension live wallpaper campaign exposes a massive structural blind spot within modern web browser extension marketplaces. Threat actors are clearly shifting away from overtly destructive malware payloads—such as keyloggers or banking trojans—and are instead mastering the art of “compliance evasion” through horizontal, multi-account mass production. By fracturing their deployment across 38 separate developer handles, the operators successfully exploit the latency inherent in manual review cycles and the isolation of automated sandbox detection.
What makes this case profoundly alarming is the sophisticated weaponization of the browser’s native developer features—like setUninstallURL—coupled with the precise spoofing of Google’s internal ved and usg cryptographic tracking signatures. This represents a dangerous transition into highly technical data-laundering fraud that severely pollutes the integrity of the global digital advertising economy. To combat this effectively, Google must evolve the Chrome Web Store security framework past primitive static code analysis and simple permission matching. There must be strict cross-verification algorithms that instantly flag absolute contradictions between dashboard data-privacy declarations, real-time client-side network telemetry, and linked privacy policy strings, alongside cryptographic integrity checks on out-of-ecosystem redirects to permanently mitigate attribution forgery.
Chrome Extension IDs
laafpeklcnlfmjaofbndehkjpnccbhekNeymar – Football Live WallpapermnpacdigbockiilmilhbedciadenfdnbSatoru Gojo Manga Live WallpaperiedplnnolciaofkakkjmcojnmklpfikgPorsche 911 – Sports Car Live Wallpaper (dead service worker)ipiabbhciknabpoihaakdahgghllelpjSatoru Gojo Live WallpaperhijpkhinofkdobfagfbobnnoihmopgkkHello Kitty Wallpapers HD New TabfamchdjojcnakamhkddkpaglnkonkfnlPusheen Cat Wallpapers HD New TabnomekamioepglinefhenifnbegjhfiaiPeach & Goma Wallpapers HD New TabjjngbcodoldjmpjpfbhfelaljbdlkekhSpider-Man Miles Morales Swing Live WallpapergfikbhpfjldbbikolkcimfgmejhdkjbeBMW M3 Neon Night Drive Live WallpaperdbiamdajndfmpmmeklcbbnekhkdcakhfBMW WallpaperspkdloppfapenphihgbldhjjlfhgnkmcgDeath Note Anime Wallpapers HD New TabimkepemaflommlonnppjobgdpokbfmojSonic Frontiers Starfall Live WallpaperibglidkppckhminbhbgcajomjplomckaTanjiro – Demon Slayer Live WallpapergkbfokaephnaajnmpgiieidpfieamggbNeymar New Tab WallpaperbcafgkhoifffmnoajkgmbhcojpabjffmAnime Car Drift Live WallpaperojeaociifmdciibodcifjjocdlbjjeepChoso Wallpapers New TabnpcghghfkbpgiamoifabankdnmopenniAnime Rain Live WallpapermjdhgndjbajnanfimjipafechjbakdhhMinecraft Sakura Pond Live WallpaperlblgjffllphdepifdkfhlihddckhlkllStraw Hat Live Wallpaper Ghost of TsushimalaeciedchhnmnfhllplcgkfcdbdfgdhnZenitsu Agatsuma Live WallpaperjhnpoiikhnkjlfcffohfbkejnoojcopcLamine Yamal Wallpapers HD FootballijbpegpcaiencppbgaldjflmllhhdfogFNAF Live WallpapericajjcahmgdpeilkbjbelkoinhonbaebRyomen Sukuna Sorcerer Live WallpaperhichkepmmfdhhnagoejglmkdebinkccaPochacco Live WallpaperhfignegjmgkcmeipgbdpaihpbnjdkgbmMessi Wallpapers HD FootballgfmgoodobmpmhoilhblgkocaehlkopodKuromi Love Live WallpapergeceobkknhgcbgnegnagckpnmfdfcppkEren Yeager Live WallpaperdnehmmlaljfhkdfekfbpljalkljgpmkjBlack Clover New Tab WallpaperdncncgaaalajgbijnalajojmmdmbdeciJon Snow Wolf Live WallpaperdmjbglakodlaodocplnbmhpdhngllhoeKuromi Wallpapers HD New TabdjfpdmpoladfinglebbgkpcbiifhpmedCinnamoroll Wallpapers HD New TabdecnpcihddaibncfimicaidmhmhfgpjbHello Kitty Friends Live WallpaperahfhmnlfmhmnifjeejhcbaffgemmkoibSung Jinwoo – Solo Leveling Live WallpapericcpkfpgkhinigpcaldpldkjpihcnginCorocoro Coronya Live WallpapercckipipbgopgoljcdhlfgcfcdkkonfbhHollow Knight Silksong Live WallpaperocdgeajebolgofbpnlahdipclagnibpmCall of Duty Ghost Live WallpapergecgngeaifpeokmajbhcmdahkkfhpgicItachi Uchiha Live WallpaperjobeagkmmpfpepbabognchgecbehljagHello Kitty Live Wallpaper SanriokfnbcjbhjiopgnlmigcigiooenpkkaibMinions Wallpapers New TabnhdniddeikmpbapjcmcoaglhgepfmopbNissan Skyline R34 Live WallpaperahheiepjhohjjdmbafjjhckninnlehlfFerrari F1 Car Live WallpaperadjkkoailfaklaipddajkpncbocgammdReal Madrid Emblem Live WallpaperiingfcnnoibkdojcnfahhflafimjikceDante Devil May Cry Live WallpapergelkonncfnniglodoncdmgcijikjdflgLabubi Live WallpaperglmagbbbkofdibipgefimkdfbppgodeeChiikawa Wallpapers New TabaeaaddfnednkbjbijieienagdilibjmoGhost Modern Warfare Live WallpaperjlnmbimmmnmejkjgaedggiignfciekimKimetsu no Yaiba Wallpapers New TabdbkhkbbjngadephedgpahlhomddaecefMiyamoto Musashi Live WallpapernmhgpefjpocdfcjenmecbnngbjbbcelpKuromi Live WallpaperbhefdfhbjonfechcjphjekhkdpaoddloKen Kaneki Tokyo Ghoul Live WallpaperafblbdldehhbfnkjaekojkkinfcdkjgnNaruto – Kakashi Hatake Live WallpapermhekafflbaidbfikbjhdfioajiahflpgAstronaut Grok Black Hole Live WallpapernhjhcfdgfphedllolofcipdnjkjdihdjHornet Hollow Knight Live WallpaperphbankjceijddhfhcobljkjlcgmbfpoaInvincible Sky Flight Live WallpapernpdbhfkphakcnjingllikjfclgabjipdPowerpuff Girls Live WallpaperjbkmnkhkobkaegbhbeimoclnljmpknngGoku & Shenron Live WallpaperafcjbeaomliemmngehinaekimohojokcMalenia – Elden Ring Live WallpaperkbbpcmlmpdbipcmkhmbnipjkpnfijndaHashibira Inosuke and Zenitsu Live WallpaperbegnlejfcmkjblajjeafpebgcbcojhinKratos Live WallpaperiipphhlmjmblpialebokpdpbnadodkbiGoku Rain Flame Live WallpaperbilaomondbfgpbokppljiindmfnackcjBlack Nissan GTR Rainy Night Live WallpapernppgecbeafccpgnhjjdlhpojicfjjbloMy Hero Academia Wallpapers New TabagfppecmpkdhfbilkkhonedjnjfnmimgDipper & Mabel’s Adventures Live WallpaperiincgojokhoknbhgjaljpihfegfpbjihHaikyuu Kenma Kozume Live WallpaperhdhcdlpopaiajpcmpnednmohdnfdmclpMy Melody Wallpapers New TabajmhcjfgeahcaccefbkmacaljjangjmcGojo Blue Eyes Live WallpaperpcokalkebdbbfpkcgejbpkjhliahlppaBerserker Armor Live WallpapereiencjmoddignmjiapafelkfgfmedpplBumblebee Live WallpaperagplicjllogkjijnddgfjincdaagkbnoLamine Yamal Galaxy Live WallpaperhpgfgaaaageiokfojfajdgjkkbadofjoArsenal FC Flag Live WallpaperhneachchlcnnfkhdiepdpoojodpjlanpRengoku Wallpapers New TabpblgphhmhlnhfkeldhflcefpckgnalmfKaonashi Live WallpaperggpncchenfmambejcehgjadnedckijafBerserker Dark Armor Live WallpaperlmaaoejgcoaieeddmdpjpmhmbpepnckfHaikyuu Wallpapers New TabkmeneimgonibpggfkjihdghpaioikppdGojo Reversal Red Live WallpaperalhilbblgdfkklanmfkbjmhapagpnengGachiakuta Wallpapers New TabgjaahnaaehopcpdhgpjddonmkgffpmjiTiger Live WallpaperdmeipihagdngmblfpfinkagindgfbmpoPurple Sakura Live WallpaperbfdcbjeogfmagcoeihgbggacohalmffmGuts Beast of Darkness Live WallpapercalbnkamaibciogbicgbgpocigocaofhBerserk Wallpapers New TabccbmjnepfjepehocnhdnddmaljhecjidDr. Stone Wallpapers New TabbdopholihfepohbcaifahepojljpihfbAnime Boy Wallpapers New TabonfjapdgahmnajmbkacmifpciokicbkdManchester United Flag Live WallpaperiggbnejemgjglnmkfjipacpfnbblkhgcBMW M4 Wallpapers New TabiagkmpcgnlcdabaheobkeffadmffoolmAce Smile One Piece Live WallpapergjlebhdhmjiahfcefjanmjcipihapcobLone Samurai Live WallpapercdokinnfpnmkkieepnnncahhgjkbnfipPorsche 911 Wallpapers New TabbbggeccdbfplmmpdbjgmkkaofbjncnkcMinecraft Creeper Live WallpaperpcadkpnfmffnldeidifelohmkebdddjnAutumn Lamborghini Live WallpaperbifidmiaihofppodiocakodjjniiodccMinato & Naruto Live WallpaperdlfjpodlhgogdiokffnejehokghbdgcaHitsugaya Toshiro Live WallpaperefdcnjhnhbnbcclppmfdgppjndkjinceNissan GTR Wallpapers New TabpfoehpcdijnjnlbeekjpndlfengadhbaBoruto Uzumaki Live WallpaperloonegbofnbcimpgbhnhlmhgfaidodbfBart Simpson Live WallpapergmcfalbhfnhpgffchgogpnlmdgalbemlAudi RS Wallpapers New TabjlkogclddcocddkbgleneedobmfcfljiKeroppi Wallpapers New TabnlllgkfjdekpcibpgakffbdlgbbbfnklGTA 6 Wallpapers New TabfeamnjpoiogkfkiihejgjlofhblfbebfDeadpool Live WallpaperobpcedpondgemjpohgikkooejmnbkpndMinecraft Sword Live WallpaperaadfnjeeifjafcgmfdjacmllmokcalccChelsea FC Live WallpaperlbjopcoldneclmibpaomiencfonnlghkRengoku Live Wallpaper Demon SlayerpcolhdbpdenlnpdhbcodnfebjkbgidafSasuke Uchiha Wallpapers New TabccbogfjhjlbclkgglnmdjommgndhaackPokemon Wallpapers New TabajhpfcgpnkmokhpkchoonflmbemhceceMercedes-AMG Wallpapers New TabdcfplngdkjdeadfbnnklpnfpannnbjpkPuss in Boots Live WallpapernplcbealebpofbdcgajeddfidbgbogaoHonda CBR1000RR-R Live WallpapernolehnmgjhncihbcganldhggmlbjplinSaitama Live Wallpaper – One Punch ManilicobgjklfepgokldofhpdolhkminomLamborghini Autumn Live WallpaperocieoagpcmmebfhhgakmlijmdnifbcagAngry Birds Wallpapers New TabdhlkhbfacnmldfohkfchjgkhkfolgapgDucati Wallpapers New TabiglemaflhcmkkepecnoibopljmocgmldAttack on Titan Wallpapers New TabeibdnpjboejipjmbkodlbcjlmdjikpjfPorsche 911 Turbo Live WallpapernoabkafiljbjmpbfafppbfclccikkaflPink Hello Kitty Live WallpaperinkcephcpbbfnikbgdklmnpjgbanginnChibi Anime Wallpapers New TabdfcklcdpnbecfbjipopoeigjipfmnmleLionel Messi Power Live WallpaperieildpjdcdcakalhlckdlfcejfddgdcjBrook Live Wallpaper – One PieceeoilhlidnimmdpafpgiehnmeoedjaggeRick and Morty Wallpapers New TabedmogjhhhoikmgdchmfgmdfnajnfpopfDenji Wallpapers New TabfjeahbfapbkbpaeijlhjokafegcgakmmMercedes-Benz E-Class Wallpapers New TabbdjlclmlpcdhiclbimfhhgpgilbeboofHarley Davidson Wallpapers New TabodkhdfbfgaogiiilllhhgaflifcppngeMickey Mouse Wallpapers New TabjcnjcmfpmcdhkhloilpalealdbofankoLamborghini Urus Wallpapers New TabnkpdoonhinmfijbgjhhehhoojicoagdiBaki Hanma Wallpapers New TabhfnikhbgpncbgfjnnccinpbijbaekaonFallout Vault Boy Live WallpapernjgifpepampdppjhncejlkkbmnigpcdlMob Psycho 100 Wallpapers New TabcnnafooohihkcoenaemoplnapabpmaakGhost of Yotei Live WallpapergjjpikdggjehfjlpgndjhjdnljenndigBMW 8 Series Wallpapers New TabcelcpebbklhbkakkmaiagcgdbfamcggoGuts Wallpapers New Tab (dead service worker)fnjofkjppepnhofinhhiobdigngbfaigHunter x Hunter Wallpapers New TabgpjofbomakaiicnnomapefkleamhphlePUBG Wallpapers New TabnphllmhkkoiaelncflmenjabjcdhpljeAggretsuko Live WallpaperlhhoicpajfbijboekonjnedpicpdijfeDark Anime Wallpapers New TabbipegidgofcllkbegbgeeoeodlglohofNaruto Live Wallpaper – Uzumaki HokagegoadfckeiedppmgdhbaceoiffbppkknfCare Bears Wallpapers New TabgjpinhcpfmeokkonngflhkolacglkpmhDoom Rampage Live WallpaperjfbalacimgcefdnniabmbejpgnhdhgngIzuku Midoriya Wallpapers New TabjpmhndngfnbfdpgdbombckddiflphpaoCristiano Ronaldo Golden Live WallpaperojlbdnmdbhjgkljldaogkoabhabjoadgGintoki Sakata Wallpapers New Tab (dead service worker)efhapddipneibbpcjogidfhbhhhlifdnKatsuki Bakugo Wallpapers New TabjoklccphgbkamedfgoeidmlcgjpdnlgjKaiju No. 8 Wallpapers New TabplbebfjeklpfmffhcknkhbbdpjfkoencAnimal Crossing – Dōbutsu no Mori Live Wallpaperjdjkbjmobobfehaohkkbenbnnaaocabc(delisted)imfibcedgmmmdikffoeipdnojhgbhjob(delisted)dljjhjgmkimljkfjboioacmepefoedlh(delisted)ijgfnklhknbjfjjbacefdgpjbkjdkfoc(delisted)ooiaicknajbjkknpnfchbgcdhmfligaj(delisted)objpdomhddblhffemlhmefbpelblakgn(delisted)kaihdoeelgmhphjindgnehgiekjeleip(delisted)dlppampnbpddlmkecbbgkgkhamchmfle(delisted)gnlmghadjomllhknpmaglmmkbabifaal(delisted)ljblneelmbapgfcbmphbnnkdofmnldjp(delisted)gdeeoecplcaghjdbpfiddgemdgdmnpbo(delisted)
