16 Fake ChatGPT Extensions Caught Hijacking User Accounts
ID: 7d3123f7-71c5-5588-8322-2fd89962dc4d
STIX ID: report--7d3123f7-71c5-5588-8322-2fd89962dc4d
Feed Name: HackRead
Researchers at LayerX Security uncovered a coordinated campaign of at least 16 malicious browser extensions masquerading as ChatGPT productivity add-ons that steal session tokens to hijack user accounts; about 900 downloads have been observed, the extensions share code, icons, and attacker-controlled domains (e.g., chatgptmods.com, Imagents.top), run with high browser privileges, and can expose connected services like Slack, GitHub, and Google Drive—users are advised to remove any unrecognized AI-linked extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
