Full Breakdown
Over 300,000 Chrome Users Targeted by Malicious AI Extensions
2/26/2026, 10:38:28 PM
Overview of the Malicious Campaign
Security researchers from LayerX have identified a significant campaign involving over 300,000 users who installed malicious Chrome extensions masquerading as artificial intelligence (AI) assistants. These extensions, which included names like AI Assistant, ChatGPT Translate, and Google Gemini, were designed to collect sensitive personal information such as emails, passwords, and browsing activity. The extensions were distributed through the official Chrome Web Store, lending them an air of legitimacy that misled users.
How the Malicious Extensions Operate
The fake AI extensions promised various helpful features, including text translation and email summarization. However, once installed, they gained permissions to view and interact with users' web activities. This access allowed them to read sensitive information, including login credentials and email content, particularly targeting Gmail accounts. The data collected was sent to servers controlled by the attackers, who could modify the extensions' behavior remotely without requiring updates.
List of Affected Extensions
The following extensions were identified as part of this malicious campaign:
- AI Assistant
- Gemini AI Sidebar
- AI Sidebar
- ChatGPT Sidebar
- Grok Asking ChatGPT
- ChatGBT
- Chat Bot GPT
- Google Gemini
- AI Translator
- AI Image Generator
- ChatGPT Ai Wallpaper Generator
Official Responses
In response to the findings, a Google spokesperson confirmed that the identified malicious extensions have been removed from the Google Web Store. However, some extensions may still be available, posing ongoing risks to users who have not yet removed them.
Criticism and User Precautions
Experts warn that the presence of these malicious extensions highlights the need for users to be vigilant about their browser security. Users are advised to regularly review and remove any suspicious or unused extensions to prevent unauthorized data collection. Additionally, changing passwords, using password managers, and installing robust antivirus software are recommended measures to enhance security.
Recommendations for Users
To mitigate risks associated with malicious extensions, users should consider the following actions:
1. Remove any suspicious or unused browser extensions.
2. Change passwords, starting with email accounts.
3. Utilize a password manager for strong, unique passwords.
4. Install and maintain active antivirus software.
5. Consider identity theft protection services.
6. Keep browsers and operating systems updated.
7. Use personal data removal services to limit exposure of personal information.
Conclusion
The discovery of these malicious AI extensions serves as a reminder that even tools designed to enhance productivity can be exploited by cybercriminals. Users are encouraged to remain proactive in managing their browser extensions and implementing security measures to protect their personal information from potential threats.
