Fake AI Chrome extensions with 300K users steal credentials, emails (www.bleepingcomputer.com)
from Zerush@lemmy.ml to security@lemmy.ml on 13 Feb 19:14
https://lemmy.ml/post/43122173

A malicious campaign of 30 Chrome extensions masquerading as AI assistants has infected over 300,000 users, stealing credentials, email content, and browsing data[^1]. The extensions, dubbed “AiFrame” by LayerX researchers, share common infrastructure under the domain tapnetic[.]pro and use iframes to load remote content rather than implementing actual AI functionality[^1].

Popular malicious extensions still available on the Chrome Web Store include:

The extensions specifically target Gmail data through content scripts that extract email content, drafts, and thread text. They can also capture voice recordings using Web Speech API and transmit data to remote servers controlled by the operators[^1].

[^1]: BleepingComputer - Fake AI Chrome extensions with 300K users steal credentials, emails

#security

threaded - newest

furzegulo@lemmy.dbzer0.com on 13 Feb 19:18 next collapse

play stupid games, win stupid prizes

OwOarchist@pawb.social on 13 Feb 19:30 collapse

AI “assistants” stealing slightly more data than usual… Who would have thought?

eldavi@lemmy.ml on 13 Feb 19:51 collapse

that’s why i’m glad i’m no longer working on anything cutting edge; just bored, old tired stuff that you could have found on stackexchange and google. lol