惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
U
Unit 42
Google DeepMind News
Google DeepMind News
博客园 - 司徒正美
Y
Y Combinator Blog
F
Fortinet All Blogs
云风的 BLOG
云风的 BLOG
T
Tailwind CSS Blog
G
Google Developers Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
D
DataBreaches.Net
T
The Blog of Author Tim Ferriss
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
MyScale Blog
MyScale Blog
N
Netflix TechBlog - Medium
Microsoft Security Blog
Microsoft Security Blog
GbyAI
GbyAI
P
Proofpoint News Feed
Jina AI
Jina AI
B
Blog RSS Feed
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
D
Docker

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Fake AI Assistants in Google Chrome Web Store Steal Passw...
2026-02-13 · via www.infosecurity-magazine.com

Photo of Danny  Palmer

Over 260,000 Google Chrome users have downloaded fake AI assistants designed to deliver malicious browser extensions which can steal login credentials, monitor emails and enable remote access by attackers.

Over 30 Google Chrome extensions designed to deliver the phoney AI assistants have been identified by cybersecurity researchers at LayerX, who describe the campaign as a “single coordinated operation.”

“Notably, several of the extensions in this campaign were featured by the Chrome Web Store, increasing their perceived legitimacy and exposure,” they said.

One of these was called ‘AI Assistant,’ which masqueraded as an extension for Anthropic’s Claude AI and was downloaded over 50,000 times. Other extensions mimicked other popular AI assistants and chatbots, including ChatGPT, Grok and Google Gemini.

The malicious extensions were published under different names and with various use cases, but the way they share underlying codebase, permissions and backend infrastructure has led researchers to suggest they all form part of one campaign they have called AiFrame, which has engaged in “extension spraying.”

This technique is used by attackers to evade takedowns, as when one extension is removed, others remain available to download, or the extension gets quickly replaced to ensure the campaign remains active.

Some of the malicious extensions direct users to infrastructure which is hosted away from the Chrome Web Store, which helped them to avoid being flagged as dangerous.

Another trick used by the fake AI assistants is based on a full screen iframe, which overlays another page over the current one. This new frame, which to the user looks like an extension of the user interface, is pointed towards a remote domain which allows the attackers to load remote content and capabilities, away from the Chrome Web Store.

This also allows the fake AI assistants to exfiltrate data from the Google Chrome Browser and Gmail to servers controlled by the attacker.

LayerX warned that the malicious extensions are “general-purpose access brokers, capable of harvesting data, monitoring user behaviour and evolving silently over time.”

“While framed as productivity tools, their architecture is incompatible with reasonable expectations of privacy and transparency,” they added.

Many of the malicious Chrome extensions now appear to have been removed from the Chrome Web Store, but users who’ve downloaded them could still be at risk.

Infosecurity has contacted Google for comment.