Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
extension-plugin-hijackcredential-stealer-activityai-platform-securityphishing-campaign-intelligence

Malicious Chrome Extensions Impersonate AI Assistants and Crypto Wallets to Steal Sensitive Data

Updated 2mo agoFirst seen Mar 6, 20264 sources

Microsoft reported a campaign of malicious Chromium-based browser extensions masquerading as legitimate AI assistant tools to harvest LLM chat histories and browsing data, with reporting suggesting ~900,000 installs and Microsoft Defender telemetry indicating activity across 20,000+ enterprise tenants. The extensions collected full URLs and chat content from services including ChatGPT and DeepSeek, creating a high-risk data leakage path for proprietary code, internal workflows, and strategic discussions; Microsoft also noted cases where “agentic” browsers auto-downloaded these extensions, reducing user friction and increasing exposure.

Separately, Socket documented a fake imToken Chrome extension (bbhaganppipihlhjgaaeeeefbaoihcgi) that posed as a benign “hex color visualizer” but functioned as a phishing redirector: on install and on click it opened attacker-controlled pages, pulling a destination URL from jsonkeeper[.]com/b/KUWNE and sending victims to chroomewedbstorre-detail-extension[.]com to solicit 12/24-word seed phrases or private keys for wallet takeover. A Kaspersky post focused on consumer guidance for disabling unwanted AI features and broadly warned about privacy/security risks from pervasive AI assistants (including mention of insecure third-party “personal agent” setups), but it did not provide corroborated details tied to the specific malicious-extension campaigns described by Microsoft and Socket.

Share:
Malicious Chrome Extensions Impersonate AI Assistants and Crypto Wallets to Steal Sensitive Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Apr 30, 20262mo ago

Unit 42 exposes 18 malicious AI-themed Chrome extensions

Palo Alto Networks Unit 42 reported 18 high-risk Chrome extensions masquerading as AI productivity tools that abused privileged browser capabilities to steal prompts, credentials, emails, API keys, and browsing data, with behaviors including remote access, adversary-in-the-browser surveillance, infostealing, spyware, and search hijacking. The researchers said Google was notified and either removed the extensions or warned their owners about policy violations.

That AI Extension Helping You Write Emails? It’s Reading Them First
Apr 3, 20263mo ago

DomainTools identifies malicious "ChatGPT Ad Blocker" Chrome extension

DomainTools reported a malicious Chrome extension named "ChatGPT Ad Blocker" that impersonated an ad blocker for ChatGPT but instead captured users’ ChatGPT conversations and exfiltrated them to a private Discord webhook. Researchers said the extension fetched remote configuration from GitHub every 60 minutes, injected code into ChatGPT pages, and was linked to the developer alias "krittinkalra."

Malicious Chrome Extension "ChatGPT Ad Blocker" Steals ChatGPT Conversations
Mar 5, 20264mo ago

Socket reports fake imToken extension to Google while it remains live

Socket disclosed that the fake imToken extension was still available in the Chrome Web Store with 39 weekly active users at the time of reporting. The company said it had reported both the extension and its publisher account to Google for removal.

Microsoft discloses technical details and mitigations for AI extension campaign

Microsoft published analysis of the malicious AI assistant extensions, describing their broad permissions, deceptive consent flows, local Base64-encoded JSON staging, and HTTPS exfiltration to attacker-controlled domains such as deepaichats[.]com and chatsaigpt[.]com. It also released mitigation guidance, Defender detections, and hunting queries for affected organizations.

Malicious AI assistant browser extensions reach large-scale distribution

Microsoft investigated a campaign involving malicious Chromium-based extensions impersonating AI assistant tools that harvested browsing data and LLM chat histories from services including ChatGPT and DeepSeek. The campaign reportedly reached about 900,000 installs and related activity was observed across more than 20,000 enterprise tenants.

Feb 2, 20265mo ago

Fake imToken Chrome extension is published to the Web Store

A malicious Chrome extension named “lmΤoken Chromophore,” impersonating the imToken wallet while posing as a color visualizer, was published in the Chrome Web Store. It used a redirector design to send users to attacker-controlled phishing pages that solicited seed phrases and private keys.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

21 LINKEDOpen in app
Affected products
5 linked
GithubDiscordChatgptChromiumMicrosoft Defender For Endpoint
Organizations
13 linked
GoogleOpenaiDiscordSocketDeepseekDomainToolsMicrosoft CorporationGitHubimTokenAITOPIAJSONKeeperWritecreamAI4ChatCo
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.