Researchers uncovered a baiting tweet that advertises Facebook Secrets, claiming to show videos that arent publicly available on the Internet. Clicking the link leads the user to a site that automatically downloads an.EXE file into the users system. The malware drops a downloader component of the visitors which downloads multiple malicious payloads bypassing Google security mechanism implemented to protect Chrome against the installation of browser extensions from third party web store. The attack starts when victims click on Facebook or Twitter shortened links, the links point to websites that automatically serve the malicious browser extension.”]
Source: https://securityaffairs.co/wordpress/28106/cyber-crime/malware-chrome-extension-security.html

