logo

LayerX Discovers Malicious Chrome Extensions Stealing ChatGPT Accounts

ID: cf502b34-ce1f-5d94-b120-7f4e8ef699ce

STIX ID: report--cf502b34-ce1f-5d94-b120-7f4e8ef699ce

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-01-27

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Researchers discovered a coordinated campaign of 16 malicious browser extensions (15 via Chrome Web Store, 1 via Microsoft Edge add-ons) that inject content scripts into chatgpt.com to intercept session tokens from authorization headers and exfiltrate them to attacker-controlled servers, enabling account-level access to ChatGPT conversations and connected services; the activity is part of a broader, ongoing trend of AI-focused malicious extensions and browser-based data-exfiltration campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.