Tag: Chrome extensions

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
News

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

A "coordinated malware campaign" that has released at least 15 malicious plugins that can steal artificial intelligence (AI) provider keys has been identified by cybersecurity researchers on the JetBrains Marketplace. According to Aikido Security researcher Ilyas Makari, each plugin poses as an AI coding helper based on DeepSeek and other large language models, providing chat, commit messages, code review, issue discovery, and unit tests. They work just as promised. Nevertheless, the AI provider API key you input is exfiltrated to a server under the attacker's control. According to reports, the activity began around the end of October 2025, and as recently as June 10, 2026, fresh plugins were made available. There are more than 25,000 downloads of two of the plugins, CodeGPT AI Assi...
Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites
News

Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites

Two malicious Google Chrome extensions with the same name and uploaded by the same developer have been found by cybersecurity researchers. These extensions have the ability to intercept communications and obtain user passwords. The extensions are marketed as a "multi-location network speed test plug-in" for foreign trade staff and developers. As of this writing, you can download both browser add-ons. The extensions' specifics are as follows: Phantom Shuttle (ID: fbfldogmkadejddihifklefknmikncaj) - 2,000 users (Published on November 26, 2017) Phantom Shuttle (ID: ocpcmfmiidofonkbodpdhgddhlcmcofd) - 180 users (Published on April 27, 2023) According to Socket security researcher Kush Pandya, users pay subscriptions ranging from ¥9.9 to ¥95.9 CNY ($1.40 to $13.50 USD), thinking ...
Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials
News

Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials

Numerous well-known Google Chrome extensions have been highlighted by cybersecurity researchers for hard-coding secrets in their code and transmitting data via HTTP, putting users' privacy and security at risk. A security researcher at Symantec's Security Technology and Response team, Yuanjing Guo, stated that a number of popular extensions "unintentionally transmit sensitive data over simple HTTP." In doing so, they reveal in plaintext browsing domains, machine IDs, operating system information, usage statistics, and even uninstall data. The unencrypted nature of network traffic also makes it vulnerable to adversary-in-the-middle (AitM) attacks, which enable malevolent actors on the same network—like a public Wi-Fi network—to intercept and, worse, alter this data, potentially with ...
New details reveal how hackers hijacked 35 Google Chrome extensions
News

New details reveal how hackers hijacked 35 Google Chrome extensions

New information has surfaced on a phishing campaign that targeted developers of Chrome browser extensions and compromised at least 35 extensions, including those from cybersecurity company Cyberhaven, to introduce code that stole data. Initial reports concentrated on Cyberhaven's security-focused extension, but further research showed that at least 35 extensions, used by almost 2,600,000 users, had the same code injected into them. According to targeted developers' complaints on Google Groups and LinkedIn, the most recent effort began around December 5, 2024. But as early as March 2024, BleepingComputer discovered previous command and control subdomains read more about New details reveal how hackers hijacked 35 Google Chrome extensions. Get up to date on the latest cybersecurity ...
Chrome extensions can steal plaintext passwords from websites
News

Chrome extensions can steal plaintext passwords from websites

A proof-of-concept extension that can extract plaintext passwords from a website's source code has been released to the Chrome Web Store by a team of researchers from the University of Wisconsin-Madison. The coarse-grained permission architecture supporting Chrome extensions breaches the concepts of least privilege and complete mediation, according to an analysis of text input fields in web browsers. The researchers also discovered that a large number of popular websites, including certain Google and Cloudflare portals, save passwords in plaintext in the HTML source code of their web pages, making it possible for extensions to access them. These websites receive millions of visitors each month read more Chrome extensions can steal plaintext passwords from websites. Stay informed ...