152 Chrome 'Wallpaper' Extensions Quietly Push Adware to 105K Browsers
A 38-account publisher cluster on the Chrome Web Store funnels new-tab traffic through three backends, and it looks a lot less like art and a lot more like an ad-fraud pipeline.

Key points
- 152 Chrome extensions posing as live wallpaper add-ons belong to a single potentially unwanted program operation.
- The cluster spans 38 publisher accounts and three brand backends:
tabplugins[.]com,yowgames[.]com, andchromewallpaper[.]com. - Combined installs across the Chrome Web Store reached 105,000.
- An extension that overrides your new tab page can inject sponsored content or redirect search queries, and is one silent update away from worse.
- Google had not confirmed enforcement action as of publication.
What exactly is this cluster?
152 extensions, 38 publisher accounts, three shared backends. Each account carries only a handful of listings, small enough to avoid casual review thresholds, numerous enough that pulling one account barely dents the network. Funneling everything through the same three backends reveals shared infrastructure for whatever monetization or telemetry fires once the extension lands. That shared backend is also the thread an investigator pulls to unravel the whole thing.
The pattern itself is familiar. Live wallpapers and new-tab overrides have been a favorite adware cover for years because the "override the new tab page" permission is precisely the lever needed to stuff ad impressions a user never requested. Think of it as the browser-extension equivalent of a typosquatted toolbar from 2008, just with nicer animations. We first reported on a Chrome Web Store PUP operation on 15 June 2026, so the store's adware problem is not new ground for this site.
Should you worry?
Adware that hijacks search is a policy violation and a privacy problem. It is also a foothold. An extension with permission to read and modify pages on every site you visit is one silent update away from something more serious. The Chrome Web Store has shipped malicious updates from previously benign extensions before, and "previously benign" is doing a lot of work in that sentence.
The Chrome Web Store's program policies explicitly prohibit deceptive installation tactics and undisclosed monetization, both of which this network appears to brush against.
What should defenders do?
Organizations running managed Chrome fleets should pull extension inventories and check network logs for the three backend domains, plus the extension IDs once published. Enterprise policy via ExtensionInstallAllowlist (a Chrome setting that blocks any extension not on an approved list) remains the cleanest control. For everyone else: audit your installed extensions and treat "live wallpaper" the way you would have treated a free screensaver download in 2003.
105,000 installs is a rounding error against Chrome's total user base. It is also 105,000 browsers running something you probably didn't want, doing things you almost certainly didn't agree to.



