Quick Summary
The Securityish Brief
More than 30 Chrome extensions, identified by LayerX Security, have been found to impersonate AI chatbots like Claude, ChatGPT, Gemini, and Grok. These extensions, which have collectively been installed by at least 260,000 users, are designed to extract sensitive data such as API keys and email content. Despite the malicious nature of these extensions, many are still available on the Chrome Web Store.
The campaign, dubbed AiFrame, employs a shared codebase and permissions across all 32 extensions, which communicate with infrastructure under the tapnetic[.]pro domain. For instance, the AI Sidebar extension, which had 50,000 users at the time of the report, reappeared under a new ID after its predecessor was removed.
Another notable extension, AI Assistant, has 60,000 users and features an iframe that allows it to load remote content, enabling the operator to modify its interface and functionality without needing an update from the Chrome Web Store. This iframe also facilitates the extraction of data from any page the user visits.
Nearly half of these extensions specifically target Gmail, using a common integration codebase that allows them to read visible email content directly from the DOM. This includes not only message text but also draft and compose-related content, which is sent to remote servers.
The implications of this campaign are significant, as it exploits the conversational nature of AI interactions, leading users to share sensitive information. By mimicking trusted AI interfaces, these extensions create a nearly invisible man-in-the-middle attack, intercepting personal data before it reaches legitimate services.
Understanding the Risks
Users and organizations should be aware of the risks posed by these malicious extensions, especially as they continue to target popular platforms like Gmail. The ability of these extensions to extract sensitive information highlights the need for vigilance when installing browser extensions.
It is crucial for users to verify the legitimacy of any AI assistant extension before installation. Given that many of these extensions have been re-uploaded under new IDs, continuous monitoring and scrutiny of installed extensions are necessary to mitigate potential data theft.
Key Takeaways
- Check your installed Chrome extensions for any that claim to be AI assistants and verify their legitimacy.
- Regularly monitor your API keys and email accounts for any unauthorized access or suspicious activity.
- Be cautious about sharing sensitive information with AI tools, as they may not be secure.
- Consider using security tools that can help identify and remove malicious browser extensions.
- Stay informed about new threats and updates regarding browser extensions to better protect your data.
Key Terms & Concepts
- Iframe: In this article, an iframe refers to a HTML element that allows an external webpage to be embedded within another webpage.
- API Key: An API key is a code passed to an API to identify the calling program, its developer, or its user to the website.
- DOM: The DOM, or Document Object Model, is a programming interface for web documents that represents the structure of a document as a tree of objects.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.