PULSE NAME
That AI Extension Helping You Write Emails? It's Reading Them First
WHITE AlienVault 2026-04-30 Modified: 2026-05-04
21
IOCs
MEDIUM VOLUME
Researchers discovered 18 malicious AI browser extensions masquerading as productivity tools that deliver remote access trojans, meddler-in-the-middle attacks, and infostealers. These extensions exploit the rise of generative AI to target prompts, user behavior, and browser sessions through API interception, passive DOM observation, traffic proxying, and HTTPS response decryption. Examples include extensions that surveil emails during composition, intercept ChatGPT prompts, and exfiltrate passwords. Multiple samples contained AI-generated code indicating threat actors employed large language models to accelerate production. Google removed or issued warnings for all 18 reported extensions. These malicious tools specifically target sensitive data including AI API keys, authentication credentials, email content, and proprietary session information by exploiting user trust in AI-branded applications.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Chrome MCP Server Supersonic AI Reverse Recruiting Chat AI for Chrome AI Photo and Video Editor Huiyi
Indicators of Compromise (6 / 21 total)
All CVE FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 0cbf101e96f6d5c4146812f07105f8b89bd76dd994f540470cd1c4bc37df37d5 2026-04-30
FileHash-SHA256 4e38bee33237a8c8b17a2504013e506ca7cbf667a7f68a2d94d75db505c2149f 2026-04-30
FileHash-SHA256 604c7aef72892b56ac23ad54744376574239c8f0651e95dd5b6cf540eb70f7c3 2026-04-30
FileHash-SHA256 ac0a312398b3bf6b3d7c5169687ca72f361838bc5a90f2c0dbce2dc8e2094a02 2026-04-30
FileHash-SHA256 c9754454efede2dec2fcb856faa40424b8df378706b664a5ae4847fcd0336b53 2026-04-30
FileHash-SHA256 dfe307d957724ebe32331f92d53e366b7fa85968a9564c2285c5a0142ac9e1bb 2026-04-30