Malicious Chrome Extensions: Affiliate Hijacking & ChatGPT Token Theft Campaign — Threadlinqs Intelligence
As of 2026-05-30, Malicious Chrome Extensions: Affiliate Hijacking & ChatGPT Token Theft Campaign is a high-severity malware threat attributed to a Russia-nexus actor, tracked by Threadlinqs Intelligence with 11 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0005 · Severity: HIGH · CVSS: 7.5 · Status: RESOLVED · Category: MALWARE
Attribution: Russia · FINANCIAL
A coordinated multi-campaign attack targeting Chrome and Edge browser extension users through affiliate link hijacking, ChatGPT session token theft, and a malware-as-a-service toolkit called Stanley
In January 2026, multiple security research teams independently uncovered a converging set of browser extension threats that weaponize the Chrome Web Store's trust model. **Cluster 1 — 10Xprofit Affiliate Hijacking (29 extensions):** Discovered by Socket Security researcher Kush Pandya, a publisher named '10Xprofit' uploaded 29 extensions to the Chrome Web Store starting January 19, 2026. The flagship 'Amazon Ads Blocker' (ID: pnpchphmplpdimbllknjoiopmfphellj) delivers advertised ad-blocking functionality while silently injecting the developer's affiliate tag '10xprofit-20' into every Amazon product URL and replacing existing affiliate codes from legitimate content creators. For AliExpress, the tag '_c3pFXV63' is used. Extensions target Amazon, AliExpress, Best Buy, Shein, Shopify, and Walmart. Product data is exfiltrated to 'app.10xprofit[.]io'. AliExpress-focused extensions inject bogus 'LIMITED TIME DEAL' countdown timers to create false urgency and rush purchases through affiliate links. **Cluster 2 — ChatGPT Mods Token Theft (16 extensions):** Discovered by LayerX Security researcher Natalie Zargarov, 16 coordinated extensions (15 Chrome, 1 Edge) masquerade as ChatGPT enhancement tools. They implement MAIN-world content script injection on chatgpt.com, hooking the browser's window.fetch API to intercept authorization headers containing ChatGPT session tokens. Stolen tokens are transmitted to attacker-controlled backends at chatgptmods[.]com and imagents[.]top. Token possession provides full account-level access including conversation history, metadata, and connected services (Google Drive, Slack, GitHub). Combined downloads: ~900. All extensions share minified codebase, consistent branding, batch upload patterns, and synchronized update timelines. **Cluster 3 — Symantec-Flagged Data Theft (4 extensions):** Broadcom/Symantec flagged 4 extensions with 100,000+ combined users: (1) 'Good Tab' grants clipboard read/write to external domain 'api.office123456[.]com' via insecure HTTP iframe, enabling clipboard hijacking for cryptocurrency wallet address swapping; (2) 'Children Protection' implements a full C&C framework with cookie harvesting, ad injection, arbitrary JavaScript execution, and domain generation algorithm (DGA) fallback using base-36 date encoding; (3) 'DPS Websafe' hijacks default search engine to developer-controlled domain while impersonating Adblock Plus branding; (4) 'Stock Informer' contains exploitable XSS via CVE-2020-28707 in Stockdio Historical Chart plugin. **Stanley MaaS Toolkit:** Separately, Varonis researcher Daniel Kelley discovered a malware-as-a-service toolkit called 'Stanley' (named after seller alias 'Стэнли') sold on a Russian-language cybercrime forum since January 12, 2026. Priced $2,000-$6,000 with the premium tier guaranteeing Chrome Web Store publication. The toolkit generates malicious Chrome extensions disguised as note-taking utilities that deploy full-screen iframe overlays showing phishing pages while the legitimate URL remains in the address bar. Features include a C2 web panel for managing victims, configuring URL-specific spoofing rules, IP-based fingerprinting, 10-second C2 polling, backup domain rotation, and Chrome notification-based luring. A proof-of-concept extension 'Notely' was identified. The C2 was taken offline January 22, 2026 after reporting, and the group went dark by January 27, but rebranding is expected.
Weaknesses (CWE)
CWE-200, CWE-522, CWE-79, CWE-346, CWE-494, CWE-862
Target sectors: E-Commerce, Technology, AI/ML Users, Content Creators, Cryptocurrency, Financial Services, Enterprise
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-26, this threat has 11 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2020-28707, T1189, T1204, T1176, T1036, T1027, T1140, T1528, T1539, T1056, T1082