# Malicious Chrome Extensions: Affiliate Hijacking and ChatGPT Token Theft Campaign

> A large-scale malicious Chrome extension campaign combining affiliate cookie hijacking and AI/ChatGPT session token theft has compromised 35+ browser extensions with 2.6+ million cumulative installations. The campaign operates through two distinct but convergent attack vectors: (1) Developer account phishing — attackers send phishing emails impersonating Google Chrome Web Store Developer Support, claiming extensions face removal for policy violations, tricking developers into granting OAuth permissions to a malicious 'Privacy Policy Extension' app, which is then used to inject malicious code into legitimate published extensions; (2) Direct malicious extension publication — fake ChatGPT/AI-branded extensions published to the Chrome Web Store that offer real ChatGPT functionality while secretly harvesting Facebook session cookies, ChatGPT access tokens, and browser data. The first variant was discovered through the Cyberhaven incident (December 24, 2024) and traced back to infrastructure registered as early as July 2021, with active compromise dating to at least April 2023. The campaign targets Facebook Ads accounts specifically — hijacked business accounts are weaponized into paid advertising infrastructure to self-propagate the malicious extensions via Facebook-sponsored posts. Cookie stuffing for affiliate fraud generates ongoing revenue alongside the credential theft. Guardio Labs, Secure Annex, and ExtensionTotal have tracked the expanding scope. Key C2 domains: cyberhavenext[.]pro, nagofsg[.]com, sclpfybn[.]com, tnagofsg[.]com. Affected extensions include AI assistants, VPNs, video tools, and productivity utilities — all categories where users grant broad permissions without scrutiny.

- **Published:** 2026-02-02T19:28:00Z
- **Last reviewed:** 2026-02-02T19:28:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0015
- **ID:** TL-2026-0015
- **Severity:** HIGH (CVSS 7.5)
- **Category:** MALWARE
- **Status:** DORMANT
- **Actor:** 10Xprofit
- **Detections:** 23 · **IOCs:** 44 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2020-28707

## Description

This campaign represents the convergence of three cybercrime business models weaponized through browser extensions: affiliate cookie hijacking (fraudulent affiliate commissions), AI platform credential theft (ChatGPT/OpenAI session tokens for resale or abuse), and Facebook Ads account hijacking (converting stolen business accounts into self-propagating malvertising infrastructure).

**Attack Vector 1 — Developer Account Phishing (Supply Chain):**
The December 2024 wave targeted extension DEVELOPERS, not end users. Attackers sent phishing emails from Google-lookalike addresses claiming the developer's extension violates Chrome Web Store policies and faces imminent removal. The email contains a link to 'accept policies' that redirects to a Google OAuth consent screen for a malicious application named 'Privacy Policy Extension.' When the developer grants consent, the attacker gains access to the developer's Chrome Web Store publishing account. The attacker then publishes a malicious update to the legitimate extension, passing Chrome's security review because the base extension is already approved. This supply-chain compromise affected at least 35 extensions with 2.6M+ total users, including Cyberhaven (data security company), VPNCity, Internxt VPN, Visual Effects for Google Meet, Reader Mode, and numerous AI-branded extensions.

**Attack Vector 2 — Fake ChatGPT Extensions (Direct Publication):**
Since early 2023, attackers have published fake ChatGPT-branded extensions (e.g., 'Quick access to Chat GPT,' 'ChatGPT For Google,' 'Chat GPT for Google,' 'FakeGPT') that offer real ChatGPT integration while secretly: (1) Harvesting Facebook session cookies from authenticated browser sessions, (2) Extracting ChatGPT/OpenAI access tokens from chat.openai.com cookies, (3) Stealing Facebook business account credentials and adding rogue admin apps ('portal' and 'msg_kig'), (4) Creating automated Facebook Ads campaigns using hijacked business accounts to promote the malicious extension — creating a self-propagating worm-like distribution loop.

**Affiliate Cookie Hijacking:**
Multiple compromised extensions include hidden 'ecommerce' functionality that performs cookie stuffing — injecting affiliate tracking cookies for major e-commerce platforms (Amazon, BestBuy, etc.) to claim commission on purchases the user makes independently. This is traced to a monetization SDK potentially linked to Urban VPN. The cookie stuffing code was found alongside the credential theft code in extensions like 'Rewards Search Automator' and 'Earny - Up to 20% Cash Back.'

**Campaign Timeline & Scale:**
- Infrastructure registered: July 2021 (sclpfybn[.]com) — campaign potentially 3.5+ years old
- First known active compromise: April 2023 ('Earny' extension)
- FakeGPT campaigns: February-March 2023 (Guardio Labs discovery)
- Mass developer phishing wave: December 2024 (Cyberhaven incident)
- Total affected extensions: 35+ confirmed, potentially more undiscovered
- Total affected users: 2.6 million+ (Chrome Web Store installation counts)
- Key researchers: Guardio Labs (Nati Tal), Secure Annex (John Tuckner), Cyberhaven, ExtensionTotal, LayerX Security (Or Eshed), Nudge Security (Jamie Blasco)

**Impact:**
(1) Facebook Ads account takeover — hijacked business accounts used for malvertising, extremist propaganda, and self-propagation
(2) ChatGPT/OpenAI token theft — session tokens enable account takeover, access to conversation history, API abuse
(3) Affiliate fraud — cookie stuffing generates fraudulent commissions on legitimate purchases
(4) Enterprise data exposure — Cyberhaven (a data security company) was compromised, potentially exposing DLP-protected data
(5) Trust erosion — Chrome Web Store review process bypassed, undermining extension ecosystem trust
(6) Self-propagating — hijacked FB Ads accounts fund promotion of the malicious extension to new victims

## MITRE ATT&CK

- T1185 Browser Session Hijacking
- T1539 Steal Web Session Cookie
- T1176 Software Extensions
- T1657 Financial Theft
- T1195 Supply Chain Compromise
- T1566 Phishing
- T1204 User Execution
- T1528 Steal Application Access Token
- T1111 Multi-Factor Authentication Interception
- T1056 Input Capture
- T1213 Data from Information Repositories
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1071 Application Layer Protocol
- T1531 Account Access Removal
- T1583 Acquire Infrastructure
- T1586 Compromise Accounts
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1594 Search Victim-Owned Websites
- T1087 Account Discovery
- T1199 Trusted Relationship
- T1098 Account Manipulation
- T1553 Subvert Trust Controls
- T1005 Data from Local System
- T1587 Develop Capabilities
- T1589 Gather Victim Identity Information

## Sources

- [Socket Security: Malicious Chrome Extension Performs Hidden Affiliate Hijacking](https://socket.dev/blog/malicious-chrome-extension-performs-hidden-affiliate-hijacking)
- [The Hacker News: Chrome Extensions Stealing ChatGPT Access](https://thehackernews.com/2026/01/researchers-uncover-chrome-extensions.html)
- [Symantec: Chrome Extensions Data Theft](https://www.security.com/threat-intelligence/chrome-extensions-are-you-getting-more-you-bargained)
- [The Hacker News: Dozens of Chrome Extensions Hacked, Exposing Millions to Data Theft](https://thehackernews.com/2024/12/16-chrome-extensions-hacked-exposing.html)
- [The Hacker News: Fake ChatGPT Chrome Extension Hijacking Facebook Accounts for Malicious Advertising](https://thehackernews.com/2023/03/fake-chatgpt-chrome-extension-hijacking.html)
- [The Hacker News: Fake ChatGPT Chrome Browser Extension Caught Hijacking Facebook Accounts](https://thehackernews.com/2023/03/fake-chatgpt-chrome-browser-extension.html)
- [Cyberhaven: Chrome Extension Security Incident Disclosure](https://www.cyberhaven.com/blog/cyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it)
- [Cyberhaven: Preliminary Technical Analysis of Malicious Chrome Extension](https://www.cyberhaven.com/engineering-blog/cyberhavens-preliminary-analysis-of-the-recent-malicious-chrome-extension)
- [Guardio Labs: FakeGPT — Open Source Turned Malicious (Facebook Account Stealer)](https://labs.guard.io/fakegpt-2-open-source-turned-malicious-in-another-variant-of-the-facebook-account-stealer-d00ef9883d61)
- [Guardio Labs: FakeGPT — Fake ChatGPT Chrome Extension Stealing Facebook Ad Accounts](https://labs.guard.io/fakegpt-new-variant-of-fake-chatgpt-chrome-extension-stealing-facebook-ad-accounts-with-4c9996a8f282)
- [Secure Annex: Cyberhaven Extension Compromise Analysis](https://secureannex.com/blog/cyberhaven-extension-compromise/)
- [ExtensionTotal: Cyberhaven Incident Live Tracker](https://www.extensiontotal.com/cyberhaven-incident-live)
- [Compromised Extensions Tracking Spreadsheet (Google Sheets)](https://docs.google.com/spreadsheets/d/15xOLbYgz5DQnCWYE6a_LXGcqYC_bNPPzdBqdLofz6-E/edit)
- [McAfee Labs: Malicious Cookie Stuffing Chrome Extensions with 1.4 Million Users](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-cookie-stuffing-chrome-extensions-with-1-4-million-users/)
- [Group-IB: Stolen ChatGPT Credentials on Dark Web Markets](https://www.group-ib.com/blog/chatgpt-stolen-credentials/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0015
