Malicious Chrome Extensions Masquerading as AI Assistants Steal User Data
- Securityish
- Privacy & Personal Security
Quick Summary
The Securityish Brief
Researchers at LayerX uncovered a malicious campaign named AiFrame, which involves 30 fake AI Chrome extensions that have been installed by more than 300,000 users. These extensions are designed to steal sensitive information, including credentials and email content, by communicating with a single domain, tapnetic[.]pro. Among the extensions, Gemini AI Sidebar was the most popular, boasting 80,000 users before it was removed from the Chrome Web Store.
Despite the removal of some extensions, others remain available, still posing risks to users. The malicious extensions do not implement AI functionality locally; instead, they load content from a remote domain using a full-screen iframe. This method allows the operators to change the extensions’ logic without needing to push updates, which can bypass review processes.
LayerX’s analysis revealed that all 30 extensions share the same internal structure, JavaScript logic, permissions, and backend infrastructure. A subset of 15 extensions specifically targets Gmail data, using scripts that read visible email content directly from the DOM and can even capture email drafts.
The extensions also feature a voice recognition mechanism that can siphon conversations from the user’s environment, depending on the permissions granted. This raises significant privacy concerns, as sensitive information may be sent to remote servers controlled by the extension operators.
Why This Matters for Your Security
This incident highlights the risks associated with browser extensions, particularly those claiming to offer AI functionalities. Users should be cautious about installing extensions from unknown sources, as they may compromise personal data. The ability of these extensions to extract data without user awareness emphasizes the need for vigilance when managing browser permissions.
Organizations and individuals should regularly monitor their installed extensions and be aware of the permissions they grant. Given the potential for these malicious extensions to remain undetected, users should consider resetting passwords for any accounts accessed through affected browsers.
- AI Sidebar (gghdfkafnhfpaooiolhncejnlgglhkhe) – 70,000 users
- AI Assistant (nlhpidbjmmffhoogcennoiopekbiglbp) – 60,000 users
- ChatGPT Translate (acaeafediijmccnjlokgcdiojiljfpbe) – 30,000 users
- AI GPT (kblengdlefjpjkekanpoidgoghdngdgl) – 20,000 users
- ChatGPT (llojfncgbabajmdglnkbhmiebiinohek) – 20,000 users
- AI Sidebar (djhjckkfgancelbmgcamjimgphaphjdl) – 10,000 users
- Google Gemini (fdlagfnfaheppaigholhoojabfaapnhb) – 10,000 users
Key Takeaways
- Check your installed Chrome extensions for any that may be part of the AiFrame campaign.
- Reset passwords for any accounts accessed through affected browsers to mitigate potential data theft.
- Review the permissions granted to your browser extensions and revoke any unnecessary access.
- Stay informed about new threats and updates related to browser security.
- Consider using reputable security tools to monitor for suspicious activity on your accounts.
Key Terms & Concepts
- AiFrame: In this article, AiFrame refers to a malicious campaign involving fake AI Chrome extensions designed to steal user data.
- iframe: An iframe is an HTML element that allows an external webpage to be embedded within another webpage, which can be exploited for malicious purposes.
- JavaScript logic: JavaScript logic refers to the programming code that defines how a web application behaves, which can be manipulated by malicious extensions.
- DOM: The DOM, or Document Object Model, is a programming interface that allows scripts to update the content, structure, and style of a document.
- permissions: Permissions in the context of browser extensions refer to the access rights granted to an extension, which can include reading and modifying data.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.