logo

16 Malicious Chrome Extensions as ChatGPT Enhancements Steals ChatGPT Logins

ID: 5b2fa57d-fe21-5b55-be9b-4337bcae5e32

STIX ID: report--5b2fa57d-fe21-5b55-be9b-4337bcae5e32

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-28

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Researchers uncovered a coordinated campaign of 16 malicious Chrome extensions distributed via the Chrome Web Store that masquerade as ChatGPT productivity tools, hook the browser's fetch API to intercept authorization headers, exfiltrate session tokens to attacker-controlled servers, and thereby grant attackers full access to victims' ChatGPT accounts and connected services; approximately 900 installs were observed and the extensions share nearly identical code, indicating a single organized operator. Organizations are advised to treat AI-integrated browser extensions as high-risk, implement extension monitoring, and restrict deep browser-integrated third-party tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.