Malicious Chrome AI Extensions Target 260,000 Users with Injected Iframes
ID: 6833da8e-0218-5390-a97a-b8fd337740ad
STIX ID: report--6833da8e-0218-5390-a97a-b8fd337740ad
Feed Name: GBHackers
Threat Score
Security researchers uncovered a coordinated campaign of ~30 malicious Chrome extensions (affecting over 260,000 installs) that masquerade as AI assistants while injecting operator-controlled iframes and content scripts to scrape page content, exfiltrate Gmail messages and drafts, capture voice transcripts, and maintain persistence; the extensions share identical code and backend infrastructure under tapnetic.pro and use extension-spraying and rotating subdomains to evade takedowns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
