16 Malicious Chrome Add-ons Disguised As ChatGPT Enhancers Nab User Data

A coordinated campaign of 16 malicious Chrome browser extensions masquerading as ChatGPT productivity boosters.

These add-ons, marketed to enhance AI interactions, secretly steal users’ ChatGPT session tokens, granting attackers full account access including conversation histories and connected data sources like Google Drive or GitHub.

The extensions, all developed by the same threat actor, exploit the booming demand for AI tools.

With legitimate ChatGPT enhancers flooding the Chrome Web Store, these fakes blend in seamlessly some even flaunt a “featured” badge claiming adherence to Chrome best practices.

So far, they’ve racked up around 900 downloads, a modest figure compared to past campaigns like GhostPoster or RolyPoly VPN.

LayerX warns this could explode, urging enterprises to restrict third-party AI extensions before they hit critical mass.

These extensions target ChatGPT’s authenticated web app by injecting content scripts into chatgpt.com.

Running in the browser’s MAIN JavaScript world not Chrome’s isolated environment they gain native access to the page’s runtime.

This lets them hook critical APIs like window.fetch, intercepting outbound requests. Once a request with an authorization header appears, the script extracts the session token.

A secondary script then exfiltrates it to a shared remote server, along with extension metadata, usage telemetry, and backend tokens.

Attackers use the stolen token for persistent impersonation, reading chats, metadata, and linked services without triggering alerts.

This technique sidesteps vulnerabilities in ChatGPT itself, relying on session hijacking. It highlights AI extensions’ risks: they demand deep integration with single-page apps, elevated privileges, and user trust.

As AI tools proliferate for productivity, they expand the browser’s attack surface, observing sensitive in-memory data invisible to traditional security.

LayerX detected the campaign early via AI-driven code similarity analysis, spotting shared minified codebases, identical icons, batch uploads, and the same backend domain across variants.

Fetch Hooking and MAIN World Execution

The core exploit unfolds in phases:

  1. Content script injects into chatgpt.com’s MAIN world, overriding window.fetch.
  2. It monitors requests, snags auth headers with tokens.
  3. Token forwards to a peer script for C2 exfiltration.

This grants “account-level access equivalent to the user,” per LayerX. Beyond tokens, leaked data enables user profiling and session correlation. One variant skips full interception but shares the pattern.

Visual Similarities
Visual Similarities (Source: Layerxsecurity)

Distributed mainly via Chrome Web Store (15 of 16), one hit Microsoft Edge Add-ons. All remain live as of publication.

Indicators Of Compromise

LayerX shared full IOCs for takedown:

IDExtension NameInstalls
lmiigijnefpkjcenfbinhdpafehaddagChatGPT folder, voice download, prompt manager, free tools – ChatGPT Mods605
obdobankihdfckkbfnoglefmdgmblcldChatGPT voice download, TTS download – ChatGPT Mods156
kefnabicobeigajdngijnnjmljehknjlChatGPT pin chat, bookmark – ChatGPT Mods18
ifjimhnbnbniiiaihphlclkpfikcdkabChatGPT message navigator, history scroller – ChatGPT Mods11
pfgbcfaiglkcoclichlojeaklcfboiehChatGPT model switch, save advanced model uses – ChatGPT Mods11
hljdedgemmmkdalbnmnpoimdedckdkhmChatGPT export, Markdown, JSON, images – ChatGPT Mods10
afjenpabhpfodjpncbiiahbknnghabdcChatGPT Timestamp Display – ChatGPT Mods13
gbcgjnbccjojicobfimcnfjddhpphaodChatGPT bulk delete, Chat manager – ChatGPT Mods11
ipjgfhcjeckaibnohigmbcaonfcjepmbChatGPT search history, locate specific messages – ChatGPT Mods11
mmjmcfaejolfbenlplfoihnobnggljijChatGPT prompt optimization – ChatGPT Mods10
lechagcebaneoafonkbfkljmbmaaoaecCollapsed message – ChatGPT Mods13
nhnfaiiobkpbenbbiblmgncgokeknnnoMulti-Profile Management & Switching – ChatGPT Mods0
hpcejjllhbalkcmdikecfngkepppokndSearch with ChatGPT – ChatGPT Mods0
hfdpdgblphooommgcjdnnmhpglleaafjChatGPT Token counter – ChatGPT Mods5
ioaeacncbhpmlkediaagefiegegknglcChatGPT Prompt Manager, Folder, Library, Auto Send – ChatGPT Mods5
jhohjhmbiakpgedidneeloaoloadlbdjChatGPT Mods – Folder Voice Download & More Free Tools17

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories