Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Malicious Chrome AI Extensions Target 260,000 Users with Injected Iframes

## Cybersecurity: Malicious AI Browser Extensions

Cybersecurity: Malicious AI Browser Extensions

With the increasing adoption of AI tools such as ChatGPT, Claude, Gemini, and Grok, there has been a rise in cybercriminal activity targeting these platforms. A recent investigation has discovered a coordinated effort involving 30 Chrome extensions, which appear to be legitimate AI assistants. These extensions have been found to possess surveillance capabilities, affecting over 260,000 users.

These Chrome extensions, while posing as AI-powered tools for tasks such as summarization, chat assistance, writing help, and Gmail integration, are using identical code, permissions, and backend infrastructure managed through the tapnetic.pro domain. They operate by embedding remote server-controlled interfaces via privileged proxies, allowing external servers access to sensitive browser functionalities.

The extensions utilize a sophisticated remote control mechanism. They inject full-screen iframes linked to operator-controlled subdomains of tapnetic.pro, overlaying the user's current webpage. This setup enables attackers to modify functionality and introduce new capabilities without Chrome Web Store updates or user notifications.

The extensions extract readable content from active browser tabs using Mozilla's Readability library, capturing titles, text, excerpts, and metadata from any page, including sensitive or authenticated pages.

A recent investigation has discovered a coordinated effort involving 30 Chrome extensions, which appear to be legitimate AI assistants.
Eleanor Tate · Thehackingpost

AI Assistant (50,000 installs) Gemini AI Sidebar (80,000 installs) AI Sidebar (50,000 installs) ChatGPT Translate (30,000 installs) AI GPT (20,000 installs) ChatGPT Sidebar (10,000 installs) AI Sidebar (9,000 installs) Google Gemini (7,000 installs) ChatGBT (1,000 installs) Ask Gemini (1,000 installs) ChatGPT Translation (1,000 installs) Chat GPT for Gmail (1,000 installs) DeepSeek Chat (1,000 installs) Email Generator AI (881 installs) AI Picture Generator (813 installs) Chat With Gemini (760 installs)

The operation employs "extension spraying" tactics to avoid detection and removal. When one extension is taken down, others remain available or are quickly republished under new identities. The tapnetic.pro domain presents a legitimate-appearing website, while real malicious activities occur through extension-controlled subdomains.

Security experts have raised concerns that these extensions compromise the browser security model, acting as general-purpose access brokers capable of data harvesting and behavior monitoring. As the popularity of generative AI continues to grow, similar threats are expected to increase. It is advised that extensions delegating core functionality to remote infrastructure be regarded as potential surveillance platforms.

Advertisement

Command and Control Domain: tapnetic[.]pro Command and Control Domain: onlineapp[.]pro Subdomain: claude.tapnetic.pro Subdomain: chatgpt.tapnetic.pro Subdomain: gemini.tapnetic.pro

Resource Development: Acquire Infrastructure (T1583) Initial Access: Drive-by Compromise (T1189) Initial Access: Trusted Relationship (T1199) Execution: Script Execution Defense Evasion: Masquerading (T1036) Credential Access: Adversary-in-the-Middle (T1557) Collection: Web Communication Data Collection Collection: Collect User's Information Command and Control: Establish Network Connection Command and Control: Web Service-Based C2 Exfiltration: Data Exfiltration

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories