Malicious ai extensions for google chrome affected over 300,000 users, stealing credentials and data
Massive malware campaign targeting chrome users
Researchers at cybersecurity firm LayerX have uncovered a large-scale campaign of malicious extensions for Google Chrome that have impacted over 300,000 users. The extensions, masquerading as AI assistants, have been stealing sensitive user data, including passwords, emails, and browsing history.

Extensions impersonate ai tools, steal data
The malicious extensions, which numbered around 30, pretended to offer intelligent features while actually communicating with a single backend domain. Instead of running AI locally, they loaded a full-screen iframe from a remote server, simulating the promised functionality. This allowed attackers to modify behavior without needing updates, avoiding further review processes.
Key Findings:- 30 extensions analyzed, part of the same malicious infrastructure
- All extensions had identical JavaScript logic, same permissions, and a common backend
- Some extensions had tens of thousands of downloads in the official Chrome store

Extensions targeted gmail, captured sensitive data
A subset of 15 extensions focused specifically on Gmail, activating scripts when the service was loaded. These scripts read visible message content from the DOM and could capture even drafts. When users enabled AI-assisted features like responses or summaries, the text was sent to attacker-controlled servers outside of Gmail's security perimeter.
Voice recognition capabilities added
Some extensions also included voice recognition, capable of transcribing audio and sending it remotely. Experts recommend reviewing LayerX's published indicators of compromise and promptly removing affected extensions and resetting all account passwords if suspicious activity is detected.
