Phantom Shuttle malicious Chrome extensions credential theft
Malware Activity
Summary
Hide ▲
Show ▼
Phantom Shuttle is a pair of malicious Google Chrome extensions that now intercept traffic, inject proxy credentials, and exfiltrate browsing data through attacker-controlled C2 infrastructure. The operation affects users visiting 170+ targeted domains and can steal passwords, cookies, API keys, access tokens, and form data. The extensions remain available as of publication, keeping the theft and traffic-manipulation risk active.
Related Happenings
Chrome Web Store malicious extensions coordinated campaign using shared C2
Campaign
First: 14.04.2026 23:33
Last: 14.04.2026 23:33
Sources 1
About this happening:
A coordinated **Chrome Web Store** extension operation is stealing **Google OAuth2 Bearer tokens**, deploying **backdoors**, and running **ad fraud** across more than **100 malici...
Chrome Web Store malicious extensions coordinated campaign using shared C2
CampaignAbout this happening: A coordinated **Chrome Web Store** extension operation is stealing **Google OAuth2 Bearer tokens**, deploying **backdoors**, and running **ad fraud** across more than **100 malici...
108 Malicious Google Chrome extensions sharing a C2 backend
Malware Activity
First: 14.04.2026 11:35
Last: 14.04.2026 11:35
Sources 1
About this happening:
**108 malicious Google Chrome extensions** were found to use the same **C2 infrastructure** to steal credentials, sessions, and browsing data while injecting ads and arbitrary Jav...
108 Malicious Google Chrome extensions sharing a C2 backend
Malware ActivityAbout this happening: **108 malicious Google Chrome extensions** were found to use the same **C2 infrastructure** to steal credentials, sessions, and browsing data while injecting ads and arbitrary Jav...
TikTok for Business phishing campaign using Turnstile and reverse proxy
Campaign
First: 26.03.2026 16:09
Last: 26.03.2026 16:09
Sources 1
About this happening:
A **phishing campaign** is targeting **TikTok for Business accounts** and uses **Cloudflare Turnstile** to block automated analysis before exposing a **reverse-proxy** credential-...
TikTok for Business phishing campaign using Turnstile and reverse proxy
CampaignAbout this happening: A **phishing campaign** is targeting **TikTok for Business accounts** and uses **Cloudflare Turnstile** to block automated analysis before exposing a **reverse-proxy** credential-...
Legitimate-looking Chrome extension prompt-poaching campaign
Campaign
First: 25.03.2026 13:00
Last: 25.03.2026 13:00
Sources 1
About this happening:
A recurring **Chrome extension** campaign is stealing **AI conversations** from users, exposing prompts, answers, and other sensitive content to attacker-controlled servers. The a...
Legitimate-looking Chrome extension prompt-poaching campaign
CampaignAbout this happening: A recurring **Chrome extension** campaign is stealing **AI conversations** from users, exposing prompts, answers, and other sensitive content to attacker-controlled servers. The a...
ShieldGuard browser-extension data-harvesting malware
Malware Activity
First: 18.03.2026 16:15
Last: 18.03.2026 16:15
Sources 1
About this happening:
A malicious **ShieldGuard** browser extension was dismantled after it was found harvesting sensitive data from **crypto users**, putting wallet and account information at risk. Th...
ShieldGuard browser-extension data-harvesting malware
Malware ActivityAbout this happening: A malicious **ShieldGuard** browser extension was dismantled after it was found harvesting sensitive data from **crypto users**, putting wallet and account information at risk. Th...
Timeline
-
23.12.2025 16:42 1 articles · 5mo ago
Phantom Shuttle extension published on November 26, 2017
Untyped PhaseThe Phantom Shuttle Chrome extension with ID fbfldogmkadejddihifklefknmikncaj was published on November 26, 2017 and later appeared as one of the two extension variants linked to the traffic-interception operation, with the listing showing 2,000 users.
Show sources
- Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites — thehackernews.com — 23.12.2025 16:42
-
23.12.2025 16:42 1 articles · 5mo ago
Phantom Shuttle extension published on April 27, 2023
Untyped PhaseThe Phantom Shuttle Chrome extension with ID ocpcmfmiidofonkbodpdhgddhlcmcofd was published on April 27, 2023 and added a newer variant to the same extension family, with the listing showing 180 users.
Show sources
- Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites — thehackernews.com — 23.12.2025 16:42
-
23.12.2025 16:42 2 articles · 5mo ago
Researchers identify malicious Phantom Shuttle Chrome extensions
Initial DisclosureCybersecurity researchers identified two malicious Google Chrome extensions named Phantom Shuttle that were published by the same developer, impersonated a network speed test and VPN service, injected hard-coded proxy credentials, and used man-in-the-middle proxies plus a C2 heartbeat to intercept traffic and capture user credentials.
Show sources
- Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites — thehackernews.com — 23.12.2025 16:42
- Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites — thehackernews.com — 23.12.2025 16:42