Tens of thousands of people have downloaded what they believed were useful AI tools for their browsers, only to give hackers a direct path into their most privateTens of thousands of people have downloaded what they believed were useful AI tools for their browsers, only to give hackers a direct path into their most private

Over 260,000 Chrome users hit by 30 fake AI extensions stealing browsing & email data

2026/02/13 03:20
4 min read

Tens of thousands of people have downloaded what they believed were useful AI tools for their browsers, only to give hackers a direct path into their most private online activity, including emails.

According to LayerX, over 260,000 Chrome users installed at least 30 malicious browser extensions masquerading as AI helpers. These claimed features, like chat support, email drafting, and content summaries, but in reality, they were quietly siphoning data in the background.

Trusted AI names used as cover

The timing was not random. With people eagerly adopting AI tools for both work and personal use, attackers seized on that excitement to slip in under the radar. The bogus extensions claimed ties to familiar AI services such as ChatGPT, Claude, Gemini, and Grok, brands that inspire instant recognition and confidence.

Although they went by different names, displayed varied logos, and carried distinct descriptions, all 30 extensions were fundamentally identical beneath the surface. They ran the same underlying code, requested the same broad permissions, and funneled data to the same concealed servers.

LayerX researchers described the approach as “extension spraying”, flooding the store with near-identical variants to evade detection and removal by Chrome Web Store moderators. The strategy paid off: several even earned “featured” placement, boosting their apparent legitimacy and helping rack up more installations.

What made these extensions particularly insidious was their method of operation. Instead of performing any genuine AI processing locally on the user’s device, they pulled in hidden full-screen overlays hosted on attacker-controlled servers, one confirmed domain being tapnetic.pro.

This setup allowed the operators to alter the extension’s behavior on the fly, without ever submitting updates through Google’s review process. Users had no way to spot the shifts.

Once active, the extensions could extract text, page titles, and other elements from any site a person visited, including protected pages that required logins, such as workplace portals or personal accounts, and relay everything to remote servers.

Gmail users in the crosshairs

Fifteen of the 30 extensions zeroed in on Gmail users specifically. LayerX dubbed this group the “Gmail integration cluster.” Marketed under separate names and pitched for different uses, all 15 shared the exact same code targeting Gmail. It injected scripts directly into Gmail’s interface, repeatedly grabbing the text of any open conversations visible on screen.

In simpler terms, full email content, including drafts and entire threads, could be pulled from Gmail and shipped off to the attackers’ servers. The report added that using Gmail’s built-in AI tools, such as smart replies or message summaries, sometimes triggered even greater capture of content, sending it beyond Google’s ecosystem.

This fits into a broader and worsening pattern. LayerX pointed out that only a month prior, they exposed 16 other extensions designed to steal session tokens from ChatGPT accounts, impacting over 900,000 users. In another case, two AI sidebar extensions leaked chat histories from DeepSeek and ChatGPT, affecting an additional 900,000 installs.

With Chrome boasting roughly 3 billion users globally and Gmail serving 2 billion, the browser’s extension ecosystem makes an especially tempting target for this kind of operation.

Anyone who is worried they’ve been hit can check LayerX’s published list of the malicious extensions. Simply head to “chrome://extensions” in your browser to inspect installed items and uninstall anything questionable. Enabling two-step verification on accounts is another smart step right now.

Zargarov delivered a blunt caution: “As generative AI continues to gain popularity, defenders should expect similar campaigns to proliferate.” Security professionals emphasize that the safest route is relying on AI features already integrated into trusted apps and platforms, rather than rolling the dice on unfamiliar third-party extensions.

The smartest crypto minds already read our newsletter. Want in? Join them.

Market Opportunity
Solchat Logo
Solchat Price(CHAT)
$0.0568
$0.0568$0.0568
-3.23%
USD
Solchat (CHAT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Pi Network Officially Enters Open Mainnet Phase III, A New Era of Crypto and Web3 Begins

Pi Network Officially Enters Open Mainnet Phase III, A New Era of Crypto and Web3 Begins

Pi Network has once again captured global crypto attention following the official announcement of its transition into Open Mainnet Phase III. This milestone re
Share
Hokanews2026/02/13 12:41
Cloud mining is gaining popularity around the world. LgMining’s efficient cloud mining platform helps you easily deploy digital assets and lead a new wave of crypto wealth.

Cloud mining is gaining popularity around the world. LgMining’s efficient cloud mining platform helps you easily deploy digital assets and lead a new wave of crypto wealth.

The post Cloud mining is gaining popularity around the world. LgMining’s efficient cloud mining platform helps you easily deploy digital assets and lead a new wave of crypto wealth. appeared on BitcoinEthereumNews.com. SPONSORED POST* As the cryptocurrency market continues its recovery, Ethereum has once again become the center of attention for investors. Recently, the well-known crypto mining platform LgMining predicted that Ethereum may surpass its previous all-time high and surge past $5,000. In light of this rare market opportunity, choosing a high-efficiency, secure, and low-cost mining platform has become the top priority for many investors. With its cutting-edge hardware, intelligent technology, and low-cost renewable energy advantages, LgMining Cloud Mining is rapidly emerging as a leader in the cloud mining industry. Ethereum: The Driving Force of the Crypto Market Ethereum is not only the second-largest cryptocurrency by market capitalization but also the backbone of the blockchain smart contract ecosystem. From DeFi (Decentralized Finance) to NFTs (Non-Fungible Tokens) and the broader Web3.0 infrastructure, most innovations are built on Ethereum. This widespread utility gives Ethereum tremendous growth potential. With the upcoming scalability upgrades, the Ethereum network is expected to offer improved performance and transaction speed—likely triggering a fresh wave of market enthusiasm. According to the LgMining research team, Ethereum’s share among institutional and retail investors continues to grow. Combined with shifting monetary policies and global economic uncertainties, Ethereum is expected to break past its previous high of over $4,000 and aim for $5,000 or more in the coming months. LgMining Cloud Mining: Unlocking a Low-Barrier Path to Wealth Traditional crypto mining often requires expensive mining rigs, stable electricity, and complex maintenance—making it inaccessible for the average person. LgMining Cloud Mining breaks down these barriers, allowing anyone to easily participate in mining Ethereum and Bitcoin without owning hardware. LgMining builds its robust and efficient mining infrastructure around three core advantages: 1. High-End Equipment LgMining uses top-tier mining hardware with exceptional computing power and reliability. The platform’s ASIC and GPU miners are carefully selected and tested to…
Share
BitcoinEthereumNews2025/09/18 03:04
Solar and Internet from Space: The Future of Global Connectivity and Energy Supply

Solar and Internet from Space: The Future of Global Connectivity and Energy Supply

Quiptik broke his promise to post weekly articles on HackerNoon. He was unable to access the internet and electricity in his home country for some reasons. Until we fix power and internet access, many voices will keep going unheard.
Share
Hackernoon2025/09/18 14:47