Over 260,000 users installed malicious AI Chrome extensions

February 17, 2026  21:58

Cybersecurity specialists at LayerX have uncovered a large-scale coordinated attack dubbed AiFrame. Attackers distributed 30 malicious Chrome extensions disguised as popular AI assistants—such as ChatGPT, Claude, Gemini, Grok, and others. Together, these extensions were installed more than 260,000 times, according to the official LayerX blog.

How the Attack Worked

Despite having different names, icons, and descriptions in the Chrome Web Store, all 30 extensions shared the same codebase and were controlled via a centralized server infrastructure. The most popular module, AI Assistant, imitated Claude’s interface and reached over 50,000 installs, even earning a “Recommended” badge in the Chrome store at one point.

The main trick: the extensions contained no malicious code locally. Instead, they loaded a full-screen iframe from a remote server. Users saw a familiar AI chatbot interface but were actually interacting with an external page controlled by attackers. This setup allowed the attackers to change functionality, inject phishing schemes, or collect data without updating the extension or undergoing Chrome Store review again.

Through the iframe, hackers could access:

  • Entered usernames and passwords
  • Gmail and other email contents
  • Browser history, cookies, and behavioral data

“Extension Spraying” – Surviving Removal

To evade takedown, attackers used an “extension spraying” strategy. If one extension was blocked, others remained active, and new clones with modified IDs quickly replaced removed ones. This allowed the campaign to persist despite user reports and Google’s interventions.

Third Major AI Attack in Three Months

AiFrame is the third large-scale campaign targeting AI service users in the last three months. Previous fake-extension schemes affected millions. Most of the 30 detected extensions have now been removed from the Chrome Web Store, but installed extensions may remain active until manually deleted.

What Users Should Do

If you installed any extension mimicking ChatGPT, Claude, Gemini, Grok, or simply named AI Assistant in recent months, check your installed extensions at chrome://extensions/ and remove any suspicious ones. Pay special attention to extensions requesting access to “all sites” or page content.

Google continues to clean up the store, but the best protection remains: avoid extensions from unknown developers and check reviews and install counts carefully.

In Short
LayerX discovered the AiFrame campaign: 30 malicious Chrome extensions disguised as AI assistants (ChatGPT, Claude, Gemini, Grok, etc.) racked up over 260,000 installs. They used iframes from a remote server to phish passwords, steal Gmail data, and track user behavior. All extensions were managed via one infrastructure, using extension spraying to bypass takedowns. Most modules are now removed, but users should manually check and delete any suspicious extensions.


 
 
 
 
  • Archive