# Malicious Chrome Extensions: Affiliate Hijacking & ChatGPT Token Theft Campaign

> A coordinated multi-campaign attack targeting Chrome and Edge browser extension users through affiliate link hijacking, ChatGPT session token theft, and a malware-as-a-service toolkit called Stanley that guarantees Chrome Web Store publication. The campaign spans 49+ malicious extensions across three distinct threat clusters: 29 '10Xprofit' affiliate hijackers, 16 'ChatGPT Mods' credential stealers, and 4 Symantec-flagged data theft extensions, collectively impacting over 100,000 users.

- **Published:** 2026-02-02T16:20:00Z
- **Last reviewed:** 2026-02-02T16:20:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0005
- **ID:** TL-2026-0005
- **Severity:** HIGH (CVSS 7.5)
- **Category:** MALWARE
- **Status:** RESOLVED
- **Detections:** 11 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2020-28707

## Description

In January 2026, multiple security research teams independently uncovered a converging set of browser extension threats that weaponize the Chrome Web Store's trust model. **Cluster 1 — 10Xprofit Affiliate Hijacking (29 extensions):** Discovered by Socket Security researcher Kush Pandya, a publisher named '10Xprofit' uploaded 29 extensions to the Chrome Web Store starting January 19, 2026. The flagship 'Amazon Ads Blocker' (ID: pnpchphmplpdimbllknjoiopmfphellj) delivers advertised ad-blocking functionality while silently injecting the developer's affiliate tag '10xprofit-20' into every Amazon product URL and replacing existing affiliate codes from legitimate content creators. For AliExpress, the tag '_c3pFXV63' is used. Extensions target Amazon, AliExpress, Best Buy, Shein, Shopify, and Walmart. Product data is exfiltrated to 'app.10xprofit[.]io'. AliExpress-focused extensions inject bogus 'LIMITED TIME DEAL' countdown timers to create false urgency and rush purchases through affiliate links. **Cluster 2 — ChatGPT Mods Token Theft (16 extensions):** Discovered by LayerX Security researcher Natalie Zargarov, 16 coordinated extensions (15 Chrome, 1 Edge) masquerade as ChatGPT enhancement tools. They implement MAIN-world content script injection on chatgpt.com, hooking the browser's window.fetch API to intercept authorization headers containing ChatGPT session tokens. Stolen tokens are transmitted to attacker-controlled backends at chatgptmods[.]com and imagents[.]top. Token possession provides full account-level access including conversation history, metadata, and connected services (Google Drive, Slack, GitHub). Combined downloads: ~900. All extensions share minified codebase, consistent branding, batch upload patterns, and synchronized update timelines. **Cluster 3 — Symantec-Flagged Data Theft (4 extensions):** Broadcom/Symantec flagged 4 extensions with 100,000+ combined users: (1) 'Good Tab' grants clipboard read/write to external domain 'api.office123456[.]com' via insecure HTTP iframe, enabling clipboard hijacking for cryptocurrency wallet address swapping; (2) 'Children Protection' implements a full C&C framework with cookie harvesting, ad injection, arbitrary JavaScript execution, and domain generation algorithm (DGA) fallback using base-36 date encoding; (3) 'DPS Websafe' hijacks default search engine to developer-controlled domain while impersonating Adblock Plus branding; (4) 'Stock Informer' contains exploitable XSS via CVE-2020-28707 in Stockdio Historical Chart plugin. **Stanley MaaS Toolkit:** Separately, Varonis researcher Daniel Kelley discovered a malware-as-a-service toolkit called 'Stanley' (named after seller alias 'Стэнли') sold on a Russian-language cybercrime forum since January 12, 2026. Priced $2,000-$6,000 with the premium tier guaranteeing Chrome Web Store publication. The toolkit generates malicious Chrome extensions disguised as note-taking utilities that deploy full-screen iframe overlays showing phishing pages while the legitimate URL remains in the address bar. Features include a C2 web panel for managing victims, configuring URL-specific spoofing rules, IP-based fingerprinting, 10-second C2 polling, backup domain rotation, and Chrome notification-based luring. A proof-of-concept extension 'Notely' was identified. The C2 was taken offline January 22, 2026 after reporting, and the group went dark by January 27, but rebranding is expected.

## MITRE ATT&CK

- T1189 Drive-by Compromise
- T1204 User Execution
- T1176 Software Extensions
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1528 Steal Application Access Token
- T1539 Steal Web Session Cookie
- T1056 Input Capture
- T1082 System Information Discovery
- T1005 Data from Local System
- T1115 Clipboard Data
- T1185 Browser Session Hijacking
- T1071 Application Layer Protocol
- T1568 Dynamic Resolution
- T1041 Exfiltration Over C2 Channel
- T1565 Data Manipulation
- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1588 Obtain Capabilities
- T1195 Supply Chain Compromise
- T1553 Subvert Trust Controls

## Sources

- [Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access](https://thehackernews.com/2026/01/researchers-uncover-chrome-extensions.html)
- [How We Discovered A Campaign of 16 Malicious Extensions Built to Steal ChatGPT Accounts](https://layerxsecurity.com/blog/how-we-discovered-a-campaign-of-16-malicious-extensions-chatgpt/)
- [Chrome Extensions: Are you getting more than you bargained for?](https://www.security.com/threat-intelligence/chrome-extensions-are-you-getting-more-you-bargained)
- [Stanley — A $6,000 Russian Malware Toolkit with Chrome Web Store Guarantee](https://www.varonis.com/blog/stanley-malware-kit)
- [Socket Security — Malicious Chrome Extension Performs Hidden Affiliate Hijacking](https://socket.dev/blog/malicious-chrome-extension-performs-hidden-affiliate-hijacking)
- [Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More](https://thehackernews.com/2026/01/weekly-recap-firewall-flaws-ai-built.html)
- [CVE-2020-28707 — XSS in Stockdio Historical Chart Plugin for WordPress](https://nvd.nist.gov/vuln/detail/CVE-2020-28707)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0005
