#chrome-extension-malware

[ follow ]
fromThe Hacker News
12 hours ago

Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool

Cybersecurity researchers have disclosed details of a malicious Google Chrome extension that's capable of stealing API keys associated with MEXC, a centralized cryptocurrency exchange (CEX) available in over 170 countries, while masquerading as a tool to automate trading on the platform. The extension, named MEXC API Automator (ID: pppdfgkfdemgfknfnhpkibbkabhghhfh), has 29 downloads and is still available on the Chrome Web Store as of writing. It was first published on September 1, 2025, by a developer named "jorjortan142."
Information security
fromThe Hacker News
1 week ago

Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users

This tactic of using browser extensions to stealthily capture AI conversations has been codenamed Prompt Poaching by Secure Annex. The two newly identified extensions "were found exfiltrating user conversations and all Chrome tab URLs to a remote C2 server every 30 minutes," OX Security researcher Moshe Siman Tov Bustan said. "The malware adds malicious capabilities by requesting consent for 'anonymous, non-identifiable analytics data' while actually exfiltrating complete conversation content from ChatGPT and DeepSeek sessions."
Privacy professionals
Information security
fromThe Hacker News
3 weeks ago

Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites

Two malicious Google Chrome extensions named 'Phantom Shuttle' intercept traffic, inject credentials, act as MITM proxies, and exfiltrate data after paid subscriptions.
Information security
fromTechzine Global
3 weeks ago

Malicious Chrome extensions disguise themselves as proxy services

Two Phantom Shuttle Chrome extensions route user traffic through attacker-controlled proxies to capture credentials, form data, session cookies, and API tokens.
[ Load more ]