16 Malicious Chrome Extensions as ChatGPT Enhancements Steals ChatGPT Logins

Parkinsond

Level 62
Thread author
Verified
Well-known
Dec 6, 2023
5,061
14,261
6,069
Researchers have uncovered a significant security threat targeting ChatGPT users through deceptive browser extensions.

A coordinated campaign involving 16 malicious Chrome extensions has been discovered, all designed to appear as legitimate productivity tools and ChatGPT enhancement applications.

These malware extensions are actively stealing ChatGPT session authentication tokens, granting attackers complete access to victims’ accounts and conversations.

Visual Similarities (Source - LayerX Research).jpg


 
Nice. Featured extension. Dev responding to users. Has Reddit sub.

Caution flags: few ratings, recent website, website domain (.com) and email domain (.top) don't match.
 
Caution flags: few ratings, recent website, website domain (.com) and email domain (.top) don't match.
I'm exta cautious; if not world-wide known extension such as uBO and dark reader, I would not dare to use.
Planning to stop using extensions at all in near future after Edge dropping support for uBO.
 
  • Like
Reactions: Khushal
I can understand why. I myself use plenty of extensions. I do use a restricted profile for important accounts.
Fortunately I use Keepass, so no need for extension; Brave has its own adblocker, and dark reader can be replaced by dark webpage flag, although its color inversion is annoying.