technology

Malicious chrome extensions steal data from over 300,000 users

Scam extensions pose as ai assistants

n

More than 300,000 Google Chrome users have been targeted by a malicious campaign that disguised itself as AI-powered tools.

nn

Extensions steal credentials, email, and browsing data

Extensions steal credentials, email, and browsing data

n

Security firm LayerX discovered the scam, which they dubbed 'AiFrame.' The 30 analyzed extensions all belonged to the same malicious infrastructure, communicating with servers under a single domain.

nn

Popular extensions had decades of thousands of downloads

n

Some of the most popular extensions, including Gemini AI Sidebar, AI Sidebar, AI Assistant, and ChatGPT Translate, accumulated tens of thousands of downloads before being removed.

nn

Extensions used javascript logic identical to ai functions

n

Instead of running AI functions locally, the extensions loaded a full-screen iframe from a remote domain to simulate promised functionality. This allowed operators to modify behavior without publishing updates, circumventing review processes.

nn

Extensions extracted sensitive data, targeted gmail users

n

The extensions also extracted content from visited pages, including sensitive authentication pages. A subset of 15 extensions specifically targeted Gmail, reading visible message content from the DOM and capturing even drafts when users activated AI-assisted features.

nn

Recon voice features allow audio transcription and remote sending

n

Some extensions integrated voice recognition capabilities, allowing for remote transcription of audio. Experts advise checking LayerX's published list of indicators of compromise and removing affected extensions, as well as resetting all account passwords.

nn

Take action to protect yourself from these scam extensions

n

Regularly review your Chrome extensions and remove any suspicious or outdated tools. Enable Chrome's 'Extensions' page to show permissions and reviews. Stay informed about security risks and follow best practices to safeguard your online activities.

nn