• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

16 Pretend ChatGPT Extensions Caught Hijacking Consumer Accounts – Hackread – Cybersecurity Information, Information Breaches, AI, and Extra

Admin by Admin
January 28, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


A bunch of 16 malicious browser extensions has been caught masquerading as ChatGPT productiveness aids in an try and hijack consumer accounts. Found by the analysis agency LayerX Safety, these add-ons don’t attempt to break into ChatGPT itself however look ahead to a consumer to log in after which snatch their digital credentials.

The marketing campaign entails no less than 16 distinct extensions, all developed by the identical menace actor. This appears to be a calculated transfer to make sure wider attain and maintain the marketing campaign alive in case one model was flagged, as others will discover their manner onto customers’ computer systems.

Whereas the marketing campaign has seen roughly 900 downloads thus far, a determine LayerX researchers name a “drop within the bucket” in comparison with huge scams like GhostPoster, the hazard lies in how a lot belief customers place in these instruments.

One model even managed to hold a “featured” badge on the Chrome Internet Retailer, giving it some air of authority. LayerX determined to go public now as a result of these “GPT optimisers” have gotten as frequent as VPNs, they usually needed to cease the menace earlier than it hit a “important mass.” These findings have been shared solely with Hackread.com.

Getting A Digital Key to Your Personal Life

The rip-off depends on stealing what are generally known as session tokens. Consider these as a short lived digital key that tells a web site you might be already logged in. By grabbing these keys, attackers can “impersonate them, permitting them to entry the entire consumer’s ChatGPT conversations, knowledge, or code,” LayerX’s safety researcher and weblog put up writer Natalie Zargarov defined.

The attain of this theft is surprisingly deep. As a result of many individuals join their AI instruments to work platforms, the hackers may probably see into personal Slack channels, GitHub code repositories, and Google Drive information.

Furthermore, the investigation revealed that the software program runs in a high-privilege a part of the browser, which implies it will probably “observe or manipulate” knowledge that conventional safety software program usually misses.

Similarities recognized within the extensions (Supply: LayerX Safety)

Marketing campaign Appears A Coordinated Assault

LayerX researchers imagine this wasn’t a sequence of accidents however a single, organised effort. As they probed additional, they recognized that 15 of those instruments have been on the Chrome retailer, whereas one was discovered on the Microsoft Edge market. All of them share the identical messy code and talk with particular attacker-controlled domains, together with chatgptmods.com and Imagents.prime.

One other troubling half is that these extensions have been principally uploaded in batches on the identical day and used practically similar icons and descriptions to look authentic.

“Most extensions within the marketing campaign present comparatively low particular person set up counts, with solely a small subset reaching larger adoption. We hope at LayerX that with this publication, the marketing campaign is stopped at an early stage with minimal influence,” the report concludes.

To remain protected, you could deal with any AI-linked extension as a high-risk utility. In case you have any “helper” instruments for ChatGPT put in that you just don’t recognise, one of the best transfer is to delete them.



Tags: AccountsBreachescaughtChatGPTcybersecurityDataextensionsFakeHackreadHijackingNewsuser
Admin

Admin

Next Post
Exploring how AI will form the way forward for work | MIT Information

Exploring how AI will form the way forward for work | MIT Information

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Minister tells UK’s Turing AI institute to concentrate on defence

Minister tells UK’s Turing AI institute to concentrate on defence

July 5, 2025
8 Greatest Mouse for Programming in India 2025

8 Greatest Mouse for Programming in India 2025

April 12, 2025

Trending.

The way to Clear up the Wall Puzzle in The place Winds Meet

The way to Clear up the Wall Puzzle in The place Winds Meet

November 16, 2025
Researchers Uncover Crucial GitHub CVE-2026-3854 RCE Flaw Exploitable by way of Single Git Push

Researchers Uncover Crucial GitHub CVE-2026-3854 RCE Flaw Exploitable by way of Single Git Push

April 29, 2026
Google Introduces Simula: A Reasoning-First Framework for Producing Controllable, Scalable Artificial Datasets Throughout Specialised AI Domains

Google Introduces Simula: A Reasoning-First Framework for Producing Controllable, Scalable Artificial Datasets Throughout Specialised AI Domains

April 21, 2026
Google DeepMind Introduces Decoupled DiLoCo: An Asynchronous Coaching Structure Reaching 88% Goodput Below Excessive {Hardware} Failure Charges

Google DeepMind Introduces Decoupled DiLoCo: An Asynchronous Coaching Structure Reaching 88% Goodput Below Excessive {Hardware} Failure Charges

April 24, 2026
5 AI Compute Architectures Each Engineer Ought to Know: CPUs, GPUs, TPUs, NPUs, and LPUs In contrast

5 AI Compute Architectures Each Engineer Ought to Know: CPUs, GPUs, TPUs, NPUs, and LPUs In contrast

April 10, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

What’s !essential #10: HTML-in-Canvas, Hex Maps, E-ink Optimization, and Extra

What’s !essential #10: HTML-in-Canvas, Hex Maps, E-ink Optimization, and Extra

May 2, 2026
OnlyBOTS: The AI-Solely Social Community

OnlyBOTS: The AI-Solely Social Community

May 2, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved