Threat reportMalwareTL-2026-0015

Malicious Chrome Extensions: Affiliate Hijacking and ChatGPT Token Theft Campaign

highDORMANT

Malicious Chrome Extensions (TL-2026-0015), also tracked as 10Xprofit, is a high-severity malware campaign scored CVSS 7.5, first published 2026-02-02. It is attributed to 10Xprofit with high confidence, affects Google Chrome Browser, references 1 CVE (CVE-2020-28707), maps to 27 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 23 detection rules and 44 indicators of compromise.

CVSS
7.5/10High
CVEs
1Referenced vulnerabilities
Techniques
27MITRE ATT&CK
Actors
110Xprofit
Detection rules
23SPL · KQL · Sigma
IOCs
44Indicators of compromise

Key facts for TL-2026-0015

Threat ID
TL-2026-0015
Also known as
10Xprofit, ChatGPT Mods, Affiliate Hijacking
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Status
DORMANT
Category
MALWARE
First published
Last reviewed
Attribution
10Xprofit
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
Technology, E-Commerce, Social Media, Advertising, Enterprise Software, AI/ML Companies
Target regions
Global
Detection rules
23
Indicators of compromise
44

How Malicious Chrome Extensions works

A large-scale malicious Chrome extension campaign combining affiliate cookie hijacking and AI/ChatGPT session token theft has compromised 35+ browser extensions with 2.6+ million cumulative installations. The campaign operates through two distinct but convergent attack vectors: (1) Developer account phishing — attackers send phishing emails impersonating Google Chrome Web Store Developer Support, claiming extensions face removal for policy violations, tricking developers into granting OAuth permissions to a malicious 'Privacy Policy Extension' app, which is then used to inject malicious code into legitimate published extensions; (2) Direct malicious extension publication — fake ChatGPT/AI-branded extensions published to the Chrome Web Store that offer real ChatGPT functionality while secretly harvesting Facebook session cookies, ChatGPT access tokens, and browser data. The first variant was discovered through the Cyberhaven incident (December 24, 2024) and traced back to infrastructure registered as early as July 2021, with active compromise dating to at least April 2023. The campaign targets Facebook Ads accounts specifically — hijacked business accounts are weaponized into paid advertising infrastructure to self-propagate the malicious extensions via Facebook-sponsored posts. Cookie stuffing for affiliate fraud generates ongoing revenue alongside the credential theft. Guardio Labs, Secure Annex, and ExtensionTotal have tracked the expanding scope. Key C2 domains: cyberhavenext[.]pro, nagofsg[.]com, sclpfybn[.]com, tnagofsg[.]com. Affected extensions include AI assistants, VPNs, video tools, and productivity utilities — all categories where users grant broad permissions without scrutiny.

This campaign represents the convergence of three cybercrime business models weaponized through browser extensions: affiliate cookie hijacking (fraudulent affiliate commissions), AI platform credential theft (ChatGPT/OpenAI session tokens for resale or abuse), and Facebook Ads account hijacking (converting stolen business accounts into self-propagating malvertising infrastructure).

**Attack Vector 1 — Developer Account Phishing (Supply Chain):** The December 2024 wave targeted extension DEVELOPERS, not end users. Attackers sent phishing emails from Google-lookalike addresses claiming the developer's extension violates Chrome Web Store policies and faces imminent removal. The email contains a link to 'accept policies' that redirects to a Google OAuth consent screen for a malicious application named 'Privacy Policy Extension.' When the developer grants consent, the attacker gains access to the developer's Chrome Web Store publishing account. The attacker then publishes a malicious update to the legitimate extension, passing Chrome's security review because the base extension is already approved. This supply-chain compromise affected at least 35 extensions with 2.6M+ total users, including Cyberhaven (data security company), VPNCity, Internxt VPN, Visual Effects for Google Meet, Reader Mode, and numerous AI-branded extensions.

**Attack Vector 2 — Fake ChatGPT Extensions (Direct Publication):** Since early 2023, attackers have published fake ChatGPT-branded extensions (e.g., 'Quick access to Chat GPT,' 'ChatGPT For Google,' 'Chat GPT for Google,' 'FakeGPT') that offer real ChatGPT integration while secretly: (1) Harvesting Facebook session cookies from authenticated browser sessions, (2) Extracting ChatGPT/OpenAI access tokens from chat.openai.com cookies, (3) Stealing Facebook business account credentials and adding rogue admin apps ('portal' and 'msg_kig'), (4) Creating automated Facebook Ads campaigns using hijacked business accounts to promote the malicious extension — creating a self-propagating worm-like distribution loop.

**Affiliate Cookie Hijacking:** Multiple compromised extensions include hidden 'ecommerce' functionality that performs cookie stuffing — injecting affiliate tracking cookies for major e-commerce platforms (Amazon, BestBuy, etc.) to claim commission on purchases the user makes independently. This is traced to a monetization SDK potentially linked to Urban VPN. The cookie stuffing code was found alongside the credential theft code in extensions like 'Rewards Search Automator' and 'Earny - Up to 20% Cash Back.'

**Campaign Timeline & Scale:** - Infrastructure registered: July 2021 (sclpfybn[.]com) — campaign potentially 3.5+ years old - First known active compromise: April 2023 ('Earny' extension) - FakeGPT campaigns: February-March 2023 (Guardio Labs discovery) - Mass developer phishing wave: December 2024 (Cyberhaven incident) - Total affected extensions: 35+ confirmed, potentially more undiscovered - Total affected users: 2.6 million+ (Chrome Web Store installation counts) - Key researchers: Guardio Labs (Nati Tal), Secure Annex (John Tuckner), Cyberhaven, ExtensionTotal, LayerX Security (Or Eshed), Nudge Security (Jamie Blasco)

**Impact:** (1) Facebook Ads account takeover — hijacked business accounts used for malvertising, extremist propaganda, and self-propagation (2) ChatGPT/OpenAI token theft — session tokens enable account takeover, access to conversation history, API abuse (3) Affiliate fraud — cookie stuffing generates fraudulent commissions on legitimate purchases (4) Enterprise data exposure — Cyberhaven (a data security company) was compromised, potentially exposing DLP-protected data (5) Trust erosion — Chrome Web Store review process bypassed, undermining extension ecosystem trust (6) Self-propagating — hijacked FB Ads accounts fund promotion of the malicious extension to new victims

MITRE ATT&CK techniques used in TL-2026-0015

collection

T1005 Data from Local System; T1056 Input Capture; T1185 Browser Session Hijacking; T1213 Data from Information Repositories

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

command-and-control

T1071 Application Layer Protocol

discovery

T1087 Account Discovery

persistence

T1098 Account Manipulation; T1176 Software Extensions

credential-access

T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

initial-access

T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing

execution

T1204 User Execution

impact

T1531 Account Access Removal; T1657 Financial Theft

defense-impairment

T1553 Subvert Trust Controls

resource-development

T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1587 Develop Capabilities

reconnaissance

T1589 Gather Victim Identity Information; T1594 Search Victim-Owned Websites

Affected products and versions in Malicious Chrome Extensions

  • Google — Chrome Browser
    Vulnerable versions: All with malicious extensions
  • Microsoft — Edge Browser
    Vulnerable versions: All with malicious extensions
  • OpenAI — ChatGPT Accounts
    Vulnerable versions: Session tokens at risk

Remediation for Malicious Chrome Extensions

Patches

  • Chrome: Update to latest version with Manifest V3 support
  • Compromised extensions: Update to latest clean version OR remove entirely and find alternatives

Immediate actions

  • Audit all installed Chrome extensions against the known compromised list (35+ extensions including AI Assistant, VPNCity, Internxt VPN, Reader Mode, Visual Effects for Google Meet, Rewards Search Automator, Earny, Castorus, Uvoice, Bookmark Favicon Changer, etc.)
  • Remove any compromised extensions immediately — even if they've been 'updated,' the malicious version may have already exfiltrated data
  • Rotate all Facebook session tokens and credentials — revoke connected apps (check facebook.com/settings → Apps and Websites → remove unknown apps especially 'portal' and 'msg_kig')
  • Rotate all ChatGPT/OpenAI session tokens — sign out of all sessions and generate new API keys if applicable
  • For Chrome extension developers: enable 2FA on Chrome Web Store developer accounts, review OAuth app authorizations, revoke any 'Privacy Policy Extension' grants

Workarounds

  • Use Chrome profiles or separate browsers for sensitive sessions (Facebook Ads management, ChatGPT with sensitive data) — isolated profiles limit extension access to cross-profile cookies
  • Use Firefox with uBlock Origin + strict permissions model for sensitive browsing — Firefox's extension sandbox is stronger than Chrome's
  • Review extension permissions before installation — decline extensions requesting 'Read and change all your data on all websites'

Longer-term hardening

  • Deploy enterprise browser extension management — allowlist approved extensions, block sideloading, monitor for new extensions via Chrome Enterprise policies
  • Implement Chrome Enterprise Extension Request workflow — users request extensions, IT approves after security review
  • Monitor for cookie-related browser extension permissions — extensions requesting 'cookies,' 'webRequest,' 'tabs,' 'storage' on all URLs are high-risk
  • Deploy browser extension security scanning (LayerX, Secure Annex, ExtensionTotal) to detect malicious behavior in installed extensions
  • Enforce Content Security Policy (CSP) headers on sensitive web applications to limit extension content script injection
  • For Facebook Ads accounts: implement Facebook Business Manager with Business Asset security settings, require admin 2FA, enable login alerts

CVEs associated with Malicious Chrome Extensions

CVE-2020-28707

Weaknesses (CWE) in Malicious Chrome Extensions

CWE-94, CWE-200, CWE-352

Timeline of Malicious Chrome Extensions

Showing the 20 most recent tracked events.

  • C2 domain sclpfybn[.]com registered — earliest known infrastructure for the malicious extension campaign, suggesting planning or operations began over 3 years before the mass December 2024 compromise wave. Source: Secure Annex analysis.
  • C2 domain nagofsg[.]com registered. This domain later linked to cookie stuffing and data exfiltration code in multiple compromised extensions. Source: Secure Annex.
  • McAfee Labs publishes report on malicious cookie stuffing Chrome extensions with 1.4 million users. Extensions modify cookies to claim affiliate commissions on e-commerce purchases. Early documentation of the affiliate hijacking technique. Source: McAfee Labs.
  • Trojanized 'ChatGPT For Google' extension uploaded to Chrome Web Store — a malicious fork of the legitimate open-source chatgpt-google-extension. Offers real ChatGPT functionality while stealing Facebook cookies. Source: Guardio Labs.
  • 'Quick access to Chat GPT' fake extension begins attracting 2,000 installations per day. Steals Facebook session cookies, creates rogue admin apps ('portal', 'msg_kig'), hijacks Facebook business accounts for self-propagating malvertising. Source: https://thehackernews.com/2023/03/fake-chatgpt-chrome-extension-hijacking.html
  • Guardio Labs publishes FakeGPT analysis — first public documentation of ChatGPT-branded extensions stealing Facebook Ads accounts. Extension creates 'elite army of Facebook bots and malicious paid media apparatus.' Self-propagating worm-like distribution. Source: Guardio Labs.
  • Trojanized 'ChatGPT For Google' removed from Chrome Web Store after accumulating 9,000+ installations. Source: Google/Guardio Labs.
  • Earliest confirmed compromise date for the developer phishing campaign — 'Earny - Up to 20% Cash Back' extension updated with ecommerce cookie stuffing code (Code3) and C2 domain tnagofsg[.]com. Source: Secure Annex timeline analysis.
  • Group-IB reports 101,134 compromised ChatGPT accounts found on dark web markets, stolen primarily via info-stealers (Raccoon, Vidar, RedLine). Demonstrates the market value of ChatGPT credentials — malicious extensions are another theft vector. Source: Group-IB.
  • Cyberhaven employee falls victim to phishing email impersonating Chrome Web Store Developer Support. Attacker grants OAuth permissions to malicious 'Privacy Policy Extension' app, publishes malicious update to Cyberhaven's browser extension. C2: cyberhavenext[.]pro. Source: Cyberhaven disclosure.
  • Malicious version of Cyberhaven extension goes live on Chrome Web Store after passing Chrome security review. Extension communicates with cyberhavenext[.]pro C2 server, exfiltrates cookies and access tokens. Source: Cyberhaven.
  • Malicious Cyberhaven extension version removed approximately 24 hours after going live. However, users with the compromised version still have the malicious code active until they update. Source: Cyberhaven.
  • Cyberhaven publicly discloses the compromise. Jamie Blasco (Nudge Security) pivots from cyberhavenext[.]pro C2 IP to identify additional C2 domains and compromised extensions. Source: Cyberhaven blog, Jamie Blasco Twitter.
  • Secure Annex and ExtensionTotal identify 35+ compromised extensions with 2.6 million+ total users. Researcher John Tuckner traces code lineages (Code1/Code2/Code3) connecting Cyberhaven attack to earlier cookie stuffing and 'safe-browsing' exfiltration campaigns dating to April 2023. Source: https://thehackernews.com/2024/12/16-chrome-extensions-hacked-exposing.html
  • Security researcher Wladimir Palant identifies that some extensions included data gathering code not from compromise but from a monetization SDK (potentially linked to Urban VPN) that stealthily exfiltrates browsing data. Developer of 'Visual Effects for Google Meet' tried to monetize with 'ad blocking library' before selling to Karma. Source: Wladimir Palant (Mastodon).
  • First Exploitation
  • Discovered
  • Disclosed
  • Threadlinqs Intelligence revalidates TL-2026-0015 — comprehensive analysis of the converging Chrome extension attack ecosystem: developer phishing supply chain, FakeGPT credential theft, affiliate cookie hijacking, and self-propagating Facebook Ads infrastructure.
  • As of 2026-05-29, this specific Cyberhaven-linked Chrome-extension affiliate-hijacking/ChatGPT-token campaign is contained and dormant: compromised extensions were pulled and replaced with clean versions within ~24h and the named C2 wave saw no further 2025-2026 expansion. The unattributed actor was never disrupted and CVE-2020-28707 is unpatched-irrelevant (not in CISA KEV); later extension-credential campaigns like Phantom Shuttle are separate operations, not successors.

Sources cited for Malicious Chrome Extensions

Detection coverage for TL-2026-0015

As of 2026-02-02, Threadlinqs Intelligence publishes 23 detection rule(s) for TL-2026-0015 across Splunk SPL, Microsoft KQL and Sigma, covering 44 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

23 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
44 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats