Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs, AitB, Infostealers, and Search Hijackers Targeting AI Users
Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs (TL-2026-0448), also tracked as 10xprofit affiliate hijacking campaign, is a high-severity malware campaign, first published 2026-05-02. It has no confirmed attribution, affects Google Chrome Web Store extensions, maps to 27 MITRE ATT&CK techniques (T1005, T1036, T1041), and is covered by 9 detection rules and 53 indicators of compromise.
Key facts for TL-2026-0448
- Threat ID
- TL-2026-0448
- Also known as
- 10xprofit affiliate hijacking campaign, Chrome MCP Server RAT, Supersonic AitB, Huiyi PAC spyware
- Severity
- HIGH
- Status
- MONITORING
- Category
- MALWARE
- First published
- 2026-05-02
- Last reviewed
- 2026-05-02
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, ai-developers, knowledge-workers, education, media, marketing, consumer, financial
- Target regions
- Global, North America, Europe, Asia Pacific, China
- Detection rules
- 9
- Indicators of compromise
- 53
Malware and tooling in Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs
Malware and tooling: Agent Risk Reminder Remover (bonhfflnjgdbnhcpjemkknlhimceckgb), Anker AIME Copilot (nbflcljmdbibeoaipongjgfmbapanipm), Ask AI - GPT chat (cjmhegifablecgkkncjddcgkjmgoacfd), Browser Cash (oaldjcdohhhibelagdhoahbedekfjjjf), Chat AI for Chrome (jhhjbaicgmecddbaobeobkikgmfffaeg), Chrome MCP Server - AI Browser Control (fpeabamapgecnidibdmjoepaiehokgda), Custom WebSocket-RAT (qubecare cluster), Google AI (pfdmleklaejjccgfhoeafapbhkjipcnj), Nano Banana (ffocfibjgakneigiajpccfcdmomlbapo), NotionAI插件 (jndldoeopjgmpakgmieaeeelhnjnfgkj), Notion中文版 v1.0.6 (pdahnbohfcekobflehebdkoemnmmempk), Notion中文版 v1.1.0 (ljlhpcabhpjdlcjhbmgjigfceppgabmk)
Unit 42 (Palo Alto Networks) disclosed 18 malicious Chrome extensions disguised as GenAI productivity tools — email assistants, ChatGPT/Notion helpers, AI translators, and Model Context Protocol (MCP) browser-control agents — with a combined ~73,400+ installs. The extensions deliver Remote Access Trojans, Adversary-in-the-Browser (AitB) email exfiltration, infostealers targeting OpenAI/Gemini/Claude API keys, search hijackers, and brand-impersonator adware. Multiple samples bear LLM-generated code fingerprints, and Google removed or warned the listed extensions following Unit 42's disclosure on 2026-04-30.
How Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs works
On 2026-04-30, Unit 42 published research identifying 18 high-risk Chrome Web Store extensions that weaponize the GenAI productivity narrative to gain over-broad host permissions (<all_urls>, chrome.debugger, chrome.webRequest, chrome.proxy, chrome.cookies, chrome.storage.sync) and then deliver six distinct malware classes against users of AI tools. The campaign exploits user trust in AI assistants — translators, email writers, ChatGPT companions, Notion sidekicks, MCP browser controllers — to install browser-resident implants that operate inside the TLS boundary and below network-monitoring controls.
The flagship Remote Access Trojan, "Chrome MCP Server — AI Browser Control" (extension ID fpeabamapgecnidibdmjoepaiehokgda, SHA256 0cbf101e96f6d5c4146812f07105f8b89bd76dd994f540470cd1c4bc37df37d5), masquerades as a local Model Context Protocol bridge and advertises "100% local processing" and "no external servers required" while opening a persistent WebSocket to wss://mcp-browser.qubecare[.]ai/chrome. The implant exposes more than 30 remote commands executable through new Function() and attaches the Chrome Debugger Protocol to decrypt HTTPS traffic in-process — a full RAT with screen, navigation, DOM, network and storage primitives. Two additional extensions (AI Agent, Ask AI - GPT chat) follow the same WebSocket-RAT pattern with infrastructure at 199.80.55[.]27:3130 and adjacent domains.
The Adversary-in-the-Browser cluster is anchored by "Supersonic AI" (ID eebihieclccoidddmjcencomodomdoei, ~30,000 installs, SHA256 ac0a312398b3bf6b3d7c5169687ca72f361838bc5a90f2c0dbce2dc8e2094a02) at gosupersonic[.]email. Content scripts harvest Gmail/Outlook message bodies, headers, and one-time passcodes directly from the rendered DOM, exfiltrating plaintext credentials and OTP codes without ever issuing observable network requests against the mail provider — bypassing CASB, DLP, and SWG controls that operate at the network layer.
The infostealer cluster targets the new high-value asset class of LLM API keys. "Reverse Recruiting — AI Job Application Assistant" (iefpkdilnfhogjbkhgnliaomoldgkdlj) reads chrome.storage.sync for OpenAI, Gemini, and Claude API keys and ships them in custom HTTP headers to api.reverserecruiting[.]io/v1/profile/sync along with full job-applicant PII (resume, salary expectations, LinkedIn). "Anker AIME Copilot," "Nano Banana," and the "Notion中文版" cluster (three near-identical Notion impersonators) round out this category, exfiltrating prompt history, session tokens, and identity material to banana.summarizer[.]one, notionapp[.]cn, and 172.16.18[.]184:5443.
The search-hijacker "Chat AI for Chrome" (jhhjbaicgmecddbaobeobkikgmfffaeg, SHA256 dfe307d957724ebe32331f92d53e366b7fa85968a9564c2285c5a0142ac9e1bb) registers chrome_settings_overrides to redirect default-search to chatgptforchrome[.]com and uses a triple-storage persistence pattern (chrome.cookies + window.localStorage + chrome.storage.sync) with chrome.cookies.onChanged listeners that resurrect any deleted tracking cookie from synced storage — propagating the hijack to every signed-in Chrome instance.
The spyware exemplar, "会译:一站式 AI 翻译 Agent" (dgeiaiglmhdhajbpfbmajaajdlfdinpi, ~20,000 installs, SHA256 c9754454efede2dec2fcb856faa40424b8df378706b664a5ae4847fcd0336b53), abuses chrome.proxy with a remotely-hosted PAC script at yiban[.]io/extension/proxy.pac and a command channel at huiyiai[.]net. Because the PAC file is fetched dynamically, operators can selectively re-route arbitrary subsets of victim traffic through attacker-controlled proxies without ever updating the extension package.
Finally, the brand-impersonator cluster ("Picsart: AI Photo Video Editor," "[Redacted]: AI Photo, Video," "Agent Risk Reminder Remover") leverages chrome.runtime.onInstalled to force-open thank-you pages on first run, redirecting through xuix[.]top to newextensioninstallweb[.]com/2025 and pic-editor-chromeextension[.]uno for affiliate-fraud monetization. Six extensions in this cluster are linked under what Unit 42 calls the "10xprofit affiliate hijacking campaign" and exhibit AI-generated code fingerprints — formulaic divider comments, identical scaffolding, and template-based structure suggesting LLM-assisted mass production of malicious code.
Unit 42 reported all 18 extensions to Google, which either removed them from the Chrome Web Store or issued policy-violation warnings to their owners. The campaign is significant for three reasons: (1) it operationalizes browser extensions as the modern equivalent of supply-chain implants for AI workflows; (2) it demonstrates that LLM-generated malware is now a measurable production technique; and (3) it targets the credential class — OpenAI/Gemini/Claude API keys — that grants pivot access to enterprise AI infrastructure beyond the compromised browser.
MITRE ATT&CK techniques used in TL-2026-0448
Collection
T1005 Data from Local System; T1056 Input Capture; T1114 Email Collection; T1185 Browser Session Hijacking; T1557 Adversary-in-the-Middle
Defense Evasion
T1036 Masquerading; T1564 Hide Artifacts
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1106 Native API
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery; T1217 Browser Information Discovery
Credential Access
T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Persistence
T1176 Software Extensions; T1547 Boot or Logon Autostart Execution
Initial Access
T1189 Drive-by Compromise; T1195 Supply Chain Compromise
Impact
defense-impairment
Affected products and versions in Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs
- Google — Chrome Web Store extensions
Vulnerable versions: 18 listed malicious extensions, combined ~73,400+ installs
Fixed in: All 18 removed or warned by Google as of 2026-04-30 - Anthropic — Claude API keys (stolen from victim browsers)
Vulnerable versions: any key stored in chrome.storage.sync of impacted users
Fixed in: rotate exposed keys - OpenAI — OpenAI API keys (stolen from victim browsers)
Vulnerable versions: any key stored in chrome.storage.sync of impacted users
Fixed in: rotate exposed keys - Google — Gemini API keys (stolen from victim browsers)
Vulnerable versions: any key stored in chrome.storage.sync of impacted users
Fixed in: rotate exposed keys - Google — Gmail (DOM-scraped via AitB extensions)
Vulnerable versions: users of Supersonic AI extension
Fixed in: uninstall, audit OAuth grants, re-enroll OTP - Microsoft — Outlook on the Web (DOM-scraped via AitB extensions)
Vulnerable versions: users of Supersonic AI extension
Fixed in: uninstall, audit OAuth grants, re-enroll OTP
Remediation for Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs
Patches
- Google has removed or warned each of the 18 extensions; ensure Chrome auto-update is enforced so removals propagate
- Update to latest Chrome stable to receive Web Store revocation telemetry
Immediate actions
- Block and force-uninstall the 18 listed Chrome extension IDs via chrome://policy ExtensionInstallBlocklist or equivalent EDR/MDM controls
- Block the C2 domains mcp-browser.qubecare.ai, gosupersonic.email, api.reverserecruiting.io, chatgptforchrome.com, huiyiai.net, yiban.io, xuix.top, newextensioninstallweb.com, banana.summarizer.one, notionapp.cn, vomet.ru, pic-editor-chromeextension.uno, browser.cash at perimeter and on endpoints
- Block C2 IPs 158.160.66.115:40000 and 199.80.55.27:3130 at egress
- Rotate all OpenAI, Gemini, Anthropic Claude, and other LLM provider API keys for any user who installed any of the 18 extensions
- Audit Gmail/Outlook OAuth grants and revoke unrecognized sessions for impacted users; force OTP/MFA re-enrollment
Workarounds
- Block the chrome.debugger and chrome.proxy permissions via ExtensionSettings runtime_blocked_hosts/runtime_allowed_hosts policy
- Restrict <all_urls> permission via ExtensionSettings policy until per-extension review is complete
Longer-term hardening
- Deploy ExtensionInstallAllowlist policy that whitelists only vetted, business-required Chrome extensions
- Enable enterprise Chrome browser management with Chrome Enterprise Premium URL filtering and DLP
- Implement browser-extension risk scoring (e.g., LayerX, Spin.AI, Squarex) and continuously monitor permission drift
- Train users on AI-themed extension social engineering — translators, MCP servers, ChatGPT helpers are top lures
- Centralize LLM API key issuance through a managed secrets broker so victim browser storage never holds production keys
Weaknesses (CWE) in Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs
CWE-506, CWE-829, CWE-922, CWE-1357
Timeline of Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs
- Unit 42 begins tracking AI-themed summarizer extensions and adware campaigns abusing chrome.runtime.onInstalled for forced-redirect monetization.
- Search hijackers and prompt-interception extensions emerge in the Chrome Web Store under GenAI productivity branding.
- Chrome MCP Server — AI Browser Control RAT (extension ID fpeabamapgecnidibdmjoepaiehokgda) observed targeting AI developers via deceptive 'local MCP bridge' branding.
- The Hacker News reports on Chrome extensions weaponized after ownership transfer, foreshadowing the Unit 42 cluster.
- Google removes or warns the 18 listed extensions for Chrome Web Store policy violations following Unit 42 disclosure.
- Unit 42 publishes 'That AI Extension Helping You Write Emails? It's Reading Them First,' disclosing 18 high-risk GenAI extensions across RAT, AitB, infostealer, search hijacker, brand impersonator, and spyware categories.
- Industry press (Infosecurity Magazine, others) amplify the Unit 42 disclosure, highlighting LLM-generated code fingerprints in the 10xprofit affiliate hijacking sub-campaign.
- Threadlinqs Intelligence ingests TL-2026-0448 for full pipeline research, simulation, and detection coverage.
- As of 2026-05-29, the 18 GenAI Chrome extensions Unit 42 disclosed (2026-04-30) were removed or warned by Google, but the uncategorized financially-motivated operators, C2 infrastructure, and AitB/RAT/API-key-theft tooling are not disrupted. This malware class demonstrably re-uploads under new IDs within weeks (parallel AITOPIA/AiFrame campaigns hit 900K+ and 260K users), so it remains a live, monitorable threat.
Sources cited for Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs
- That AI Extension Helping You Write Emails? It's Reading Them First
- Unit 42 — High-Risk GenAI Browser Extensions (vendor blog)
- Unit 42 prior research: Gemini Live in Chrome hijacking
- The Hacker News — Chrome Extension Turns Malicious After Ownership Transfer
- Infosecurity Magazine — Chrome Extension Uses AI Engine to Act Without User Input
- Chrome Web Store policy — Limited Use of User Data
- Chrome Enterprise — ExtensionInstallBlocklist policy
- MITRE ATT&CK T1176.002 — Browser Extensions
Threats related to Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs
Detection coverage for TL-2026-0448
As of 2026-05-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0448 across Splunk SPL, Microsoft KQL and Sigma, covering 53 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.