AiFrame malicious Chrome extension campaign
Campaign
Summary
Hide ▲
Show ▼
The AiFrame campaign uses fake AI assistants in the Chrome Web Store to distribute 30 malicious Chrome extensions that can steal email content, browser content, and sensitive data. Researchers at LayerX said the add-ons impersonate tools such as Gemini AI Sidebar and ChatGPT Translate, while routing prompts through attacker-controlled infrastructure. The campaign has drawn more than 260,000 downloads, and some extensions were still available more than 24 hours after LayerX published its findings.
Related Happenings
ModHeader browser extension hidden browsing-history collector
Malware Activity
H score42
First: 13.07.2026 20:17
Last: 13.07.2026 20:17
Sources 1
About this happening:
The ModHeader browser extension shipped a hidden browsing-history collector in its official store version, exposing about 1.6 million installs to covert domain and...
ModHeader browser extension hidden browsing-history collector
Malware ActivityAbout this happening: The ModHeader browser extension shipped a hidden browsing-history collector in its official store version, exposing about 1.6 million installs to covert domain and...
Search for perplexity ai malicious Chrome extension
Malware Activity
H score29
First: 29.06.2026 21:40
Last: 29.06.2026 21:40
Sources 1
About this happening:
A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
Search for perplexity ai malicious Chrome extension
Malware ActivityAbout this happening: A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
Commercial adware and traffic-attribution-fraud affiliate operation using Chrome extensions
Threat Actor Meta
H score20
First: 15.06.2026 14:07
Last: 15.06.2026 14:07
Sources 1
About this happening:
Researchers found a commercial adware and traffic-attribution-fraud affiliate operation abusing Chrome extensions to fabricate traffic signals and monetize installs, i...
Commercial adware and traffic-attribution-fraud affiliate operation using Chrome extensions
Threat Actor MetaAbout this happening: Researchers found a commercial adware and traffic-attribution-fraud affiliate operation abusing Chrome extensions to fabricate traffic signals and monetize installs, i...
Chrome extension PUP distribution network with fake organic traffic
Malware Activity
H score18
First: 15.06.2026 14:07
Last: 15.06.2026 14:07
Sources 1
About this happening:
A network of 152 Google Chrome extensions is distributing a potentially unwanted program (PUP) family through new-tab live-wallpaper add-ons, creating a broad browser-base...
Chrome extension PUP distribution network with fake organic traffic
Malware ActivityAbout this happening: A network of 152 Google Chrome extensions is distributing a potentially unwanted program (PUP) family through new-tab live-wallpaper add-ons, creating a broad browser-base...
AI chatbot cryptojacking campaign targeting high-performance GPU users
Campaign
H score51
First: 27.05.2026 10:45
Last: 27.05.2026 10:45
Sources 1
About this happening:
Microsoft warned of an active cryptojacking campaign that uses SEO poisoning and, in some cases, AI chatbot recommendations to steer users to malicious ZIP downloa...
AI chatbot cryptojacking campaign targeting high-performance GPU users
CampaignAbout this happening: Microsoft warned of an active cryptojacking campaign that uses SEO poisoning and, in some cases, AI chatbot recommendations to steer users to malicious ZIP downloa...
Timeline
-
12.02.2026 15:41 4 articles · 5mo ago
AiFrame malicious Chrome extension campaign disclosed
Initial DisclosureLayerX identified AiFrame, a coordinated campaign of 30 malicious Chrome extensions installed by more than 300,000 users that masquerade as AI assistants to steal credentials, email content, and browsing information from Chrome users. The extensions share internal structure, JavaScript logic, permissions, and backend infrastructure under tapnetic[.]pro; a subset of 15 targets Gmail on mail.google.com at document_start, and the operators can also collect voice and transcript data through Web Speech API and remote control.
Show sources
- Fake AI Chrome extensions with 300K users steal credentials, emails — www.bleepingcomputer.com — 12.02.2026 15:41
- Fake AI Chrome extensions with 300K users steal credentials, emails — www.bleepingcomputer.com — 12.02.2026 15:41
- Fake AI Assistants in Google Chrome Web Store Steal Passwords and Spy on Emails — www.infosecurity-magazine.com — 13.02.2026 13:25
- 260K+ Chrome Users Duped by Fake AI Browser Extensions — www.darkreading.com — 16.02.2026 16:00