This document analyzes a Facebook spam campaign that exploited users through malicious browser extensions. The spam spread by tricking users into installing a fake "YouTube Premium" extension that stole users' cookies and used them to post spam messages on friends' walls. The document traces how the extension redirected users to a page containing a distracting video while running a script in the background to spread the spam. It concludes with tips on how to avoid similar scams by being wary of suspicious browser extensions and unsolicited promises of gifts or money online.