{"id":25660,"date":"2025-01-09T09:10:11","date_gmt":"2025-01-09T17:10:11","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2025\/01\/09\/news-19383\/"},"modified":"2025-01-09T09:10:11","modified_gmt":"2025-01-09T17:10:11","slug":"news-19383","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2025\/01\/09\/news-19383\/","title":{"rendered":"Google Chrome AI extensions deliver info-stealing malware in broad attack"},"content":{"rendered":"\n<p>Small businesses and boutique organizations should use caution when leaning on browser-friendly artificial intelligence (AI) tools to generate ideas, content, and marketing copy, as a set of Google Chrome extensions were recently compromised to deliver info-stealing malware disguised as legitimate updates.<\/p>\n<p>Analyzed by researchers at Extension Total, the cybercriminal campaign has managed to take over the accounts of at least 36 Google Chrome extensions that provide AI and VPN services. The compromised extensions include \u201cBard AI Chat,\u201d \u201cChatGPT for Google Meet,\u201d \u201cChatGPT App,\u201d \u201cChatGPT Quick Access,\u201d \u201cVPNCity,\u201d \u201cInternxt VPN,\u201d <a href=\"https:\/\/www.extensiontotal.com\/cyberhaven-incident-live\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">and more<\/a>, which are used by an estimated total of 2.6 million people.<\/p>\n<p>Though these browser extensions borrow the names of the most popular AI tools available today, they are third-party tools that are not developed by Open AI\u2014the company behind ChatGPT\u2014or Google.<\/p>\n<p>In response to the attack, many of the compromised browser extensions removed their tools from the Google Chrome web store to protect users. However, other extensions remain available and in the control of cybercriminals, making them dangerous to download.<\/p>\n<p>There isn\u2019t a startup, small business, or solo practitioner today who can run their operations without a web browser, and the most popular web browser in the world\u2014<a href=\"https:\/\/en.wikipedia.org\/wiki\/Usage_share_of_web_browsers\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">by far<\/a>\u2014is Google Chrome.<\/p>\n<p>But this cybercriminal campaign has not compromised Google Chrome itself.<\/p>\n<p>Instead, it has compromised a series of extensions for Google Chrome that could prove attractive to many small businesses looking to harness AI, whether to write email newsletters, edit blogs, or even get ideas for marketing strategies in the new year. These third-party browser extensions, when they were still available, allowed users to directly ask questions to AI tools without needing to navigate away from a current web page.<\/p>\n<p>But with the new attack, those same browser extensions are now delivering fraudulent updates that carry malicious code that can steal an employee\u2019s data.<\/p>\n<p>According to <a href=\"https:\/\/www.cyberhaven.com\/engineering-blog\/cyberhavens-preliminary-analysis-of-the-recent-malicious-chrome-extension\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">an investigation published<\/a> by one of the compromised browser extension companies, the malware used in this attack sought data for Facebook Ads accounts. That may sound like a narrow goal, but considering that so many businesses rely on promotion and visibility through Facebook Ads, it isn\u2019t uncommon that this information might be stored on an employee\u2019s computer.<\/p>\n<p>For a full list of compromised extensions, <a href=\"https:\/\/www.extensiontotal.com\/cyberhaven-incident-live\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">visit here<\/a>.<\/p>\n<p>Until fixes are released for every compromised extension, warn your employees about which browser extensions are safe to use, and consider creating a policy about only trusting first-party browser extensions for work.<\/p>\n<p>For all other threats, try <a href=\"https:\/\/www.malwarebytes.com\/teams\" target=\"_blank\" rel=\"noreferrer noopener\">Malwarebytes Teams<\/a>, which provides always-on protection against malware, ransomware, spyware, and more, along with 24\/7 dedicated, human support.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2025\/01\/google-chrome-ai-extensions-deliver-info-stealing-malware-in-broad-attack\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> At least 36 Google Chrome extensions for AI and VPN tools have begun delivering info-stealing malware in a widespread attack.  <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[29737,19414,28405,10699,11425,1670,32],"class_list":["post-25660","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-bard","tag-browser-extensions","tag-chatgpt","tag-chrome","tag-extension","tag-google","tag-news"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=25660"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25660\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=25660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=25660"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=25660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}