PULSE NAME
That AI Extension Helping You Write Emails? It's Reading Them First
WHITE AlienVault 2026-04-30 Modified: 2026-05-04
21
IOCs
MEDIUM VOLUME
Researchers discovered 18 malicious AI browser extensions masquerading as productivity tools that deliver remote access trojans, meddler-in-the-middle attacks, and infostealers. These extensions exploit the rise of generative AI to target prompts, user behavior, and browser sessions through API interception, passive DOM observation, traffic proxying, and HTTPS response decryption. Examples include extensions that surveil emails during composition, intercept ChatGPT prompts, and exfiltrate passwords. Multiple samples contained AI-generated code indicating threat actors employed large language models to accelerate production. Google removed or issued warnings for all 18 reported extensions. These malicious tools specifically target sensitive data including AI API keys, authentication credentials, email content, and proprietary session information by exploiting user trust in AI-branded applications.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Chrome MCP Server Supersonic AI Reverse Recruiting Chat AI for Chrome AI Photo and Video Editor Huiyi
Indicators of Compromise (7 / 21 total)
All CVE FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain chatgptforchrome.com 2026-04-30
domain gosupersonic.email 2026-04-30
domain newextensioninstallweb.com 2026-04-30
domain notionapp.cn 2026-04-30
domain pic-editor-chromeextension.uno 2026-04-30
domain vomet.ru 2026-04-30
domain xuix.top 2026-04-30