Popular 'coupon finder' extension caught siphoning session cookies
A browser extension with over 300,000 installs was found quietly exporting session cookies from logged-in banking and email tabs in the background.
- Filed
- Aug 5, 2026
- Region
- Chrome Web Store, global
- Filed By
- Dispatch Desk
- Read Time
- 7 min read
A widely installed 'automatic coupon finder' browser extension has been found to quietly collect and transmit session cookies from any open tab matching a hardcoded list of banking, email, and social media domains — effectively enabling account takeover without ever capturing a password.
How it was discovered
A reader working in web security noticed the extension making periodic background requests to a domain unrelated to its coupon-checking function. Inspecting the traffic showed the payload contained serialized cookie data from other open tabs, not from the shopping site the extension was supposedly active on.
What the extension actually does
- Requests broad host permissions during install, framed as necessary for 'finding coupons across all shopping sites'
- Uses those permissions to read cookies from a much wider domain list, including major webmail and banking domains, hardcoded into the extension's code
- Sends that cookie data to a remote server roughly every twenty minutes while the browser is open
Because session cookies can be used to impersonate an already-logged-in session, this bypasses the need for a password or even two-factor authentication on many sites — the attacker simply reuses the stolen session.
If you have this extension installed
Remove it immediately, then sign out of all active sessions on your important accounts — most banking and email providers have a 'sign out of all devices' option in security settings, which invalidates the stolen cookies. Change your passwords as a precaution, and enable two-factor authentication if you haven't already, since a fresh login will require it again.
Broader takeaway
Extension permission prompts are worth reading literally: an extension that only needs to read the page you're actively shopping on should not be requesting access to 'all sites.' If a coupon or shopping tool asks for broad host permissions, that scope itself is worth treating as a warning sign, independent of this specific case.