Malicious actors have created 32 malicious Google Chrome extensions masquerading as ChatGPT, Google Gemini, and other AI chatbots to exfiltrate emails, API keys, and other sensitive information as part of the AiFrame campaign, The Register reports.Identical codebases and permissions have been observed across all the extensions, which have been downloaded at least 260,000 times, an analysis from LayerX Security showed. One of the extensions, AI Assistant, was discovered to have an iframe overlay enabling remote content loading and covert feature updates without requiring a Chrome Web Store update. Aside from transmitting extracted site metadata, text content, titles, and excerpts to the remote iframe, AI Assistant, which is still available on the Chrome Web Store, also enabled transcription."The campaign exploits the conversational nature of AI interactions, which has conditioned users to share detailed information. By injecting iframes that mimic trusted AI interfaces, they've created a nearly invisible man-in-the-middle attack that intercepts everything from API keys to personal data before it ever reaches the legitimate service," said LayerX Security researcher Natalie Zargarov.
AI/ML, Data Security
AI chatbot-spoofing Chrome extensions facilitate data theft

(Adobe Stock)
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



