Threat reportMalwareTL-2026-0005

Malicious Chrome Extensions: Affiliate Hijacking & ChatGPT Token Theft Campaign

highRESOLVED

Malicious Chrome Extensions (TL-2026-0005), also tracked as 10Xprofit Extensions, is a high-severity malware campaign scored CVSS 7.5, first published 2026-02-02. It carries a reported Russia nexus and is not formally attributed, affects Google Chrome Web Store / Chrome Browser, references 1 CVE (CVE-2020-28707), maps to 22 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 11 detection rules and 21 indicators of compromise.

CVSS
7.5/10High
CVEs
1Referenced vulnerabilities
Techniques
22MITRE ATT&CK
Actors
0Not attributed
Detection rules
11SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-0005

Threat ID
TL-2026-0005
Also known as
10Xprofit Extensions, ChatGPT Mods, GlassWorm Campaign, Stanley Toolkit
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Status
RESOLVED
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
E-Commerce, Technology, AI/ML Users, Content Creators, Cryptocurrency, Financial Services, Enterprise
Target regions
Global, North America, Europe
Detection rules
11
Indicators of compromise
21

Malware and tooling in Malicious Chrome Extensions

Malware and tooling: Stanley

How Malicious Chrome Extensions works

A coordinated multi-campaign attack targeting Chrome and Edge browser extension users through affiliate link hijacking, ChatGPT session token theft, and a malware-as-a-service toolkit called Stanley that guarantees Chrome Web Store publication. The campaign spans 49+ malicious extensions across three distinct threat clusters: 29 '10Xprofit' affiliate hijackers, 16 'ChatGPT Mods' credential stealers, and 4 Symantec-flagged data theft extensions, collectively impacting over 100,000 users.

In January 2026, multiple security research teams independently uncovered a converging set of browser extension threats that weaponize the Chrome Web Store's trust model. **Cluster 1 — 10Xprofit Affiliate Hijacking (29 extensions):** Discovered by Socket Security researcher Kush Pandya, a publisher named '10Xprofit' uploaded 29 extensions to the Chrome Web Store starting January 19, 2026. The flagship 'Amazon Ads Blocker' (ID: pnpchphmplpdimbllknjoiopmfphellj) delivers advertised ad-blocking functionality while silently injecting the developer's affiliate tag '10xprofit-20' into every Amazon product URL and replacing existing affiliate codes from legitimate content creators. For AliExpress, the tag '_c3pFXV63' is used. Extensions target Amazon, AliExpress, Best Buy, Shein, Shopify, and Walmart. Product data is exfiltrated to 'app.10xprofit[.]io'. AliExpress-focused extensions inject bogus 'LIMITED TIME DEAL' countdown timers to create false urgency and rush purchases through affiliate links. **Cluster 2 — ChatGPT Mods Token Theft (16 extensions):** Discovered by LayerX Security researcher Natalie Zargarov, 16 coordinated extensions (15 Chrome, 1 Edge) masquerade as ChatGPT enhancement tools. They implement MAIN-world content script injection on chatgpt.com, hooking the browser's window.fetch API to intercept authorization headers containing ChatGPT session tokens. Stolen tokens are transmitted to attacker-controlled backends at chatgptmods[.]com and imagents[.]top. Token possession provides full account-level access including conversation history, metadata, and connected services (Google Drive, Slack, GitHub). Combined downloads: ~900. All extensions share minified codebase, consistent branding, batch upload patterns, and synchronized update timelines. **Cluster 3 — Symantec-Flagged Data Theft (4 extensions):** Broadcom/Symantec flagged 4 extensions with 100,000+ combined users: (1) 'Good Tab' grants clipboard read/write to external domain 'api.office123456[.]com' via insecure HTTP iframe, enabling clipboard hijacking for cryptocurrency wallet address swapping; (2) 'Children Protection' implements a full C&C framework with cookie harvesting, ad injection, arbitrary JavaScript execution, and domain generation algorithm (DGA) fallback using base-36 date encoding; (3) 'DPS Websafe' hijacks default search engine to developer-controlled domain while impersonating Adblock Plus branding; (4) 'Stock Informer' contains exploitable XSS via CVE-2020-28707 in Stockdio Historical Chart plugin. **Stanley MaaS Toolkit:** Separately, Varonis researcher Daniel Kelley discovered a malware-as-a-service toolkit called 'Stanley' (named after seller alias 'Стэнли') sold on a Russian-language cybercrime forum since January 12, 2026. Priced $2,000-$6,000 with the premium tier guaranteeing Chrome Web Store publication. The toolkit generates malicious Chrome extensions disguised as note-taking utilities that deploy full-screen iframe overlays showing phishing pages while the legitimate URL remains in the address bar. Features include a C2 web panel for managing victims, configuring URL-specific spoofing rules, IP-based fingerprinting, 10-second C2 polling, backup domain rotation, and Chrome notification-based luring. A proof-of-concept extension 'Notely' was identified. The C2 was taken offline January 22, 2026 after reporting, and the group went dark by January 27, but rebranding is expected.

MITRE ATT&CK techniques used in TL-2026-0005

collection

T1005 Data from Local System; T1056 Input Capture; T1115 Clipboard Data; T1185 Browser Session Hijacking

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

exfiltration

T1041 Exfiltration Over C2 Channel

command-and-control

T1071 Application Layer Protocol; T1568 Dynamic Resolution

discovery

T1082 System Information Discovery

persistence

T1176 Software Extensions

initial-access

T1189 Drive-by Compromise; T1195 Supply Chain Compromise

execution

T1204 User Execution

credential-access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

defense-impairment

T1553 Subvert Trust Controls

impact

T1565 Data Manipulation

resource-development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities

Affected products and versions in Malicious Chrome Extensions

  • Google — Chrome Web Store / Chrome Browser
    Vulnerable versions: All versions with malicious extensions installed
    Fixed in: Remove malicious extensions
  • Microsoft — Edge Add-ons / Edge Browser
    Vulnerable versions: All versions with malicious extensions installed
    Fixed in: Remove malicious extensions
  • OpenAI — ChatGPT
    Vulnerable versions: Web interface sessions exposed via token theft
    Fixed in: Revoke and rotate session tokens

Remediation for Malicious Chrome Extensions

Immediate actions

  • Audit all installed Chrome/Edge extensions against provided IOC extension IDs
  • Remove any extensions matching the 29 10Xprofit IDs, 16 ChatGPT Mods IDs, or 4 Symantec-flagged IDs
  • Revoke and rotate ChatGPT session tokens if any ChatGPT Mods extensions were installed
  • Reset affiliate program credentials if affiliate hijacking is suspected
  • Check clipboard history for unauthorized modifications if Good Tab was installed

Workarounds

  • Disable or remove all untrusted browser extensions
  • Use browser profiles with minimal extensions for sensitive activities like banking and AI platforms
  • Monitor network traffic for connections to known C2 domains

Longer-term hardening

  • Implement browser extension allowlisting via Chrome Enterprise or Edge for Business
  • Deploy behavior-based extension monitoring for unauthorized network activity and DOM manipulation
  • Classify AI-integrated extensions as privileged applications requiring additional security review
  • Periodically audit installed extensions and remove unused ones
  • Restrict extensions requesting all_urls or broad host permissions

CVEs associated with Malicious Chrome Extensions

CVE-2020-28707

Weaknesses (CWE) in Malicious Chrome Extensions

CWE-200, CWE-522, CWE-79, CWE-346, CWE-494, CWE-862

Timeline of Malicious Chrome Extensions

  • Stanley MaaS toolkit first appeared on a Russian-language cybercrime forum, advertised by seller alias 'Стэнли' with pricing from $2,000-$6,000 and Chrome Web Store publication guarantee.
  • First Exploitation
  • Publisher '10Xprofit' uploaded 'Amazon Ads Blocker' and the first batch of 29 affiliate hijacking extensions to the Chrome Web Store.
  • Varonis reported Stanley toolkit to Chrome Web Store and hosting provider.
  • Stanley C2 server was taken offline following Varonis disclosure to hosting provider.
  • Varonis published technical analysis of Stanley MaaS toolkit detailing C2 panel, iframe overlay spoofing, IP fingerprinting, and backup domain rotation.
  • Stanley 'Notely' extension removed from Chrome Web Store. Seller group went dark, likely prompted by public disclosure.
  • Broadcom/Symantec reported 4 malicious extensions (Good Tab, Children Protection, DPS Websafe, Stock Informer) with combined 100,000+ users to Google for removal from Chrome Web Store.
  • LayerX published full IOC list including 16 extension IDs, C2 domains chatgptmods[.]com and imagents[.]top, and technical analysis of MAIN-world fetch API hooking for session token interception.
  • Socket Security, LayerX, and Broadcom/Symantec simultaneously disclosed findings on 10Xprofit affiliate hijackers (29 extensions), ChatGPT Mods token stealers (16 extensions), and data theft extensions (4 extensions).
  • Disclosed
  • Discovered
  • As of 2026-05-29, this Jan-2026 campaign is concluded: 10Xprofit/Symantec/ChatGPT-Mods extensions were reported to Google/Microsoft and the publisher vanished by Jan 27, while Stanley's C2 went offline Jan 22 and the seller went dark with no confirmed successor surfacing. CVE-2020-28707 is a 2020 low-severity Stockdio XSS, patched in v2.8.1 and absent from CISA KEV, so no residual active exploitation remains.

Sources cited for Malicious Chrome Extensions

Detection coverage for TL-2026-0005

As of 2026-02-02, Threadlinqs Intelligence publishes 11 detection rule(s) for TL-2026-0005 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

11 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats