logo

Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials

ID: 05ef522f-a162-52a7-a017-a3ab9f6a8f59

STIX ID: report--05ef522f-a162-52a7-a017-a3ab9f6a8f59

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2025-12-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Two malicious Chrome extensions marketed as VPN/proxy “Phantom Shuttle” have been distributed via the Chrome Web Store to over 2,180 users; they perform real proxy/latency functions while covertly intercepting HTTP authentication, injecting hardcoded proxy credentials, and exfiltrating plaintext email/passwords and other browsing data to a C2 (phantomshuttle.space) on a regular heartbeat—researchers observed obfuscated JS, use of chrome.webRequest.onAuthRequired in asyncBlocking mode, and continuous credential theft prompting takedown requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.