Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History
ID: 992c3913-33e5-58bb-b353-c30cf7bea9be
STIX ID: report--992c3913-33e5-58bb-b353-c30cf7bea9be
Feed Name: The Hacker News
Multiple malicious Chrome-extension campaigns are actively abusing the Chrome Web Store to harvest high-value data and enable account takeover: CL Suite exfiltrates TOTP seeds and Meta/Facebook Business Manager exports (enabling 2FA bypass and targeted follow-on attacks); VK Styles has silently hijacked ~500,000 VK accounts via injected JavaScript and persistent settings manipulation; the AiFrame cluster and dozens of fake AI/Gmail assistant extensions (≈260k installs) relay email content and browser data to remote servers, and a separate study found 287 extensions (≈37.4M installs) leaking browsing history to data brokers. The report provides extension IDs, attacker infrastructure (e.g., getauth.pro, claude.tapnetic.pro), and observed techniques for remote payloads and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
