logo

Malicious Chrome AI Extensions Attacking 260,000 Users via Injected IFrames

ID: 1d6b5b5e-e3cd-5ab3-ac72-0c46ce3ec081

STIX ID: report--1d6b5b5e-e3cd-5ab3-ac72-0c46ce3ec081

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-02-13

Date Updated: 2026-04-21

Author: Abinaya

...
...

Security researchers uncovered a coordinated campaign of malicious Chrome extensions (impersonating ChatGPT, Gemini, Grok, etc.) that have been installed by over 260,000 users. The extensions load attacker-controlled full-screen iframes (e.g., subdomains of tapnetic.pro/onlineapp.pro) to remotely change behavior, capture tab content and voice input, track installs/uninstalls, and a cluster of Gmail-focused extensions scrape email content and exfiltrate it to attacker servers. Operators replace removed extensions by uploading clones with new IDs, use themed subdomains that point to the same backend, and rely on multiple Gmail accounts to manage/publish extensions; defenders are advised to audit AI-branded extensions, monitor for iframe injections and Gmail DOM access, and watch outbound traffic to the identified domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.