16 Malicious Chrome Extensions as ChatGPT Enhancements Steals ChatGPT Logins
Researchers have identified a coordinated campaign involving 16 malicious Chrome extensions that target ChatGPT users. These extensions, disguised as productivity tools and ChatGPT enhancements, are designed to steal ChatGPT session authentication…
Researchers have identified a coordinated campaign involving 16 malicious Chrome extensions that target ChatGPT users. These extensions, disguised as productivity tools and ChatGPT enhancements, are designed to steal ChatGPT session authentication tokens, providing attackers with unauthorized access to users' accounts and conversations.
The campaign exploits the increasing popularity of AI-powered browser extensions. As users seek to enhance productivity with such tools, threat actors have recognized an opportunity to exploit this trend. The extensions use names and branding that mimic legitimate productivity applications, making it difficult for users to differentiate between authentic and malicious software.
LayerX Research analysts identified this campaign through advanced detection methods and code analysis. The analysis revealed that all 16 extensions share similar malicious code, indicating a single threat actor is likely behind this large-scale operation.
Session Token Interception and Account Access
The infection mechanism involves session token interception. When users install one of these malicious extensions, it injects code into pages where ChatGPT is accessed. This code hooks into the browser's functions, specifically targeting the window.fetch function, which handles web requests. This allows the malware to monitor all outgoing traffic from ChatGPT's official site.
Researchers have identified a coordinated campaign involving 16 malicious Chrome extensions that target ChatGPT users.
When the extension detects requests containing authorization headers, it extracts these session tokens and transmits them to attacker-controlled servers. With these tokens, attackers can impersonate users, accessing ChatGPT conversations, stored data, and connected services such as Google Drive, Slack, and GitHub.
This approach grants account-level access without the need to crack passwords or exploit vulnerabilities, often evading traditional security tools.
The malicious extensions also collect additional data, including extension metadata and usage telemetry. This information allows attackers to maintain persistent access to compromised accounts and identify user behavior patterns.
The campaign has resulted in approximately 900 installations across all variants. However, researchers warn that this number could rise as AI-focused extensions become more widely adopted.
Organizations and users should consider AI-integrated browser extensions as high-risk software requiring careful evaluation before deployment. Security teams must implement extension monitoring technologies and establish policies restricting third-party AI tools that require deep browser integration.
Based on reporting by Cyber Security News.
