30+ Chrome extensions disguised as AI chatbots steal users' API keys, emails, other sensitive data
ID: 3663f2b3-d04e-55e5-b50e-4ec1a936c600
STIX ID: report--3663f2b3-d04e-55e5-b50e-4ec1a936c600
Feed Name: The Register (Security)
LayerX Security uncovered a campaign of 32 malicious Chrome extensions (AiFrame) that impersonate AI chatbots and assistant tools to steal API keys, email contents, and other sensitive data. The extensions load remote iframes (hosted under tapnetic.pro) that can change UI/logic, extract page and Gmail DOM content—including drafts and visible messages—and transmit transcribed speech and authentication details to remote servers; collectively they have impacted roughly 260,000 users and remain available on the Chrome Web Store.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
