Story perspectives
Malicious Chrome Extensions Hijack User Data Since 2017
1/5/2026
1 of 1
Story summary
- Two malicious Chrome extensions, including "Phantom Shuttle," have hijacked user data since 2017 by routing web traffic through attacker-controlled servers.
- They were marketed as proxy tools and were available on the Chrome Web Store.
- Google removed them from the Chrome Web Store.
- Users should review installed extensions, install only necessary ones, and check publisher credibility.
