Skip to content
DnsLister Forum

Where domain hunters compare notes

Did anyone else get their session cookies stolen after using Helium Browser?

A few weeks ago, my Facebook account was suddenly compromised. They didn’t even change my password; they just started blasting scam messages to my friends list. I was actively logged into my own session, and no new foreign device showed up in the device list. However, under the active session details, there was a ghost entry explicitly labeled as "FB Internal Thrift over HTTP". This means an automated bot script had hijacked my raw session cookies/tokens and was hitting Meta's internal RPC/Thrift endpoints directly using my credentials.

I didn’t take any chances—I immediately formatted my PC, did a clean Windows install, and manually changed every single account password. I thought I had contained it.

Then, just today, Google flagged a "Suspicious activity detected" alert and forcibly terminated a Windows session. The kicker? The log stated that the session had been active since August 26. Since my PC is freshly formatted and my credentials are brand new, this was clearly an attacker attempting to reuse an old, stolen session cookie/token harvested before the format. Google rejected it because the token had been revoked, but it completely confirmed that my browser session states were hijacked late last month.

Here is what’s driving me crazy: I’m very strict about my network setup. I constantly monitor my DNS queries and local traffic, and there were zero anomalous requests, weird outbound connections, or suspicious ports being hit. At first, I wondered if I might have caught an RCE exploit while playing GTA Online, but given how clean this credential/DPAPI extraction was without setting off any network triggers, that seems far-fetched.

Looking at what was actually running on my machine back then, the only real anomaly left is Helium Browser. Being a custom browser fork, it had native access to my session cookies and local storage, meaning it wouldn’t even need an elevation exploit or weird network behavior to pull this off if something was rogue.

(I honestly doubt my extensions had anything to do with it, but for full context:

  • Pre-format: uBlock Origin, AdGuard, Google Scholar PDF Reader
  • Post-format: uBlock Origin, Google Scholar PDF Reader)

Has anyone else noticed unauthorized logins, stolen tokens, or session hijacking after using Helium? Trying to see if there’s an ongoing supply chain/dependency issue with it, or if I’m chasing the wrong suspect.

Source: r/cybersecurity_help · by /u/Fit-Swimmer-270

Leave a Reply

Your email address will not be published. Required fields are marked *