logo

Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

ID: 5f530976-08ca-5de8-a5a3-2d85fbbcca68

STIX ID: report--5f530976-08ca-5de8-a5a3-2d85fbbcca68

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-01-30

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Security researchers uncovered coordinated networks of malicious Chrome (and Edge) extensions that hijack affiliate links across e-commerce sites, scrape and exfiltrate product data to attacker-controlled endpoints, and intercept ChatGPT authentication tokens by injecting content scripts into chatgpt.com; the clusters include dozens of extensions (many listed by ID), have evidence of active distribution and abuse (some with large user counts), and are complemented by a commercial 'Stanley' malware-as-a-service kit that generates phishing-capable extensions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.