logo

Malicious extensions in Chrome Web store steal user credentials

ID: 9c4c6efc-cf46-540f-8e61-22eb1cf38a2d

STIX ID: report--9c4c6efc-cf46-540f-8e61-22eb1cf38a2d

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-12-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers found two Chrome Web Store extensions called 'Phantom Shuttle' that pose as proxy tools but route user traffic through attacker-controlled proxies (using hardcoded credentials and an obfuscated encoding scheme), intercept HTTP authentication challenges, and can capture credentials, payment details, session cookies and API tokens; the extensions have been active since at least 2017 and target users in China while routing traffic for over 170 high-value domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.