LayerX Security discovered 16 malicious Chrome extensions disguised as ChatGPT productivity tools that steal user session tokens to hijack accounts. The extensions intercept authentication tokens and send them to remote servers, allowing attackers to access conversation histories and metadata. This campaign, with about 900

5m read timeFrom securityboulevard.com
Post cover image
Table of contents
An Ongoing ThreatThe Broader TrendMalicious Optimizers Hidden Among Popular OnesA Lot of Extensions, a Single Campaign

Sort: