152 Chrome 'Wallpaper' Extensions Quietly Push Adware to 105K Browsers
A 38-account publisher cluster on the Chrome Web Store funnels new-tab traffic through three backends — and it looks a lot less like art and a lot more like an ad-fraud pipeline.

Researchers have mapped a sprawl of 152 Chrome extensions masquerading as new-tab live wallpaper add-ons, all of which appear to belong to a single potentially unwanted program operation.
The numbers are unflattering. 38 publisher accounts. Three brand backends — tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com. Roughly 105,000 combined installs across the Chrome Web Store.
That's not a botnet. But it's not nothing.
The pattern is one Chrome security folks know well: cute consumer hook, broad permissions, monetization in the back room. Live wallpapers and new-tab overrides have been a favorite cover for adware families going back years, because the "override the new tab page" permission is exactly the lever you need to inject sponsored content, redirect search queries, or fire off impressions a user never asked for.
Think of it as the browser-extension equivalent of a typosquatted toolbar from 2008, just with nicer animations.
The cluster's structure is what makes this interesting rather than routine. 152 extensions spread across 38 publisher accounts means each account is carrying only a handful of listings — small enough to stay under casual review thresholds, large enough that takedowns of any one account barely dent the network. Funneling all of them into three backends suggests shared infrastructure for whatever monetization or telemetry is happening once the extension is installed.
That shared backend is also the thread an investigator pulls to unravel the whole thing.
For defenders, the practical question is whether any of this rises above nuisance-ware. Adware that hijacks search or stuffs ad impressions is a policy violation and a privacy problem, but it's also a foothold. An extension with permissions to read and modify pages on every site you visit is one silent update away from being something worse. The Chrome Web Store has shipped malicious updates from previously benign extensions before, and "previously benign" is doing a lot of work in that sentence.
Organizations running managed Chrome fleets should pull extension inventories and look for any of the three backend domains in network logs, plus the extension IDs once they're published. Enterprise policy via ExtensionInstallAllowlist remains the cleanest control. For everyone else: audit your installed extensions, and treat "live wallpaper" the same way you'd treat a free screensaver download in 2003.
Google has not, as of writing, commented on the cluster or confirmed enforcement action. The Chrome Web Store's program policies explicitly prohibit deceptive installation tactics and undisclosed monetization, both of which this network appears to brush up against.
105,000 installs is a rounding error against Chrome's user base. It's also 105,000 browsers with an extension you probably didn't want doing things you probably didn't agree to.



