Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs, AitB, Infostealers, and Search Hijackers Targeting AI Users — Threadlinqs Intelligence
As of 2026-05-30, Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs, AitB, Infostealers, and Search Hijackers Targeting AI Users is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 53 indicators of compromise.
Threat ID: TL-2026-0448 · Severity: HIGH · Status: MONITORING · Category: MALWARE
Unit 42 (Palo Alto Networks) disclosed 18 malicious Chrome extensions disguised as GenAI productivity tools — email assistants, ChatGPT/Notion helpers, AI translators, and Model Context Protocol (MCP)
On 2026-04-30, Unit 42 published research identifying 18 high-risk Chrome Web Store extensions that weaponize the GenAI productivity narrative to gain over-broad host permissions (<all_urls>, chrome.debugger, chrome.webRequest, chrome.proxy, chrome.cookies, chrome.storage.sync) and then deliver six distinct malware classes against users of AI tools. The campaign exploits user trust in AI assistants — translators, email writers, ChatGPT companions, Notion sidekicks, MCP browser controllers — to install browser-resident implants that operate inside the TLS boundary and below network-monitoring controls.
The flagship Remote Access Trojan, "Chrome MCP Server — AI Browser Control" (extension ID fpeabamapgecnidibdmjoepaiehokgda, SHA256 0cbf101e96f6d5c4146812f07105f8b89bd76dd994f540470cd1c4bc37df37d5), masquerades as a local Model Context Protocol bridge and advertises "100% local processing" and "no external servers required" while opening a persistent WebSocket to wss://mcp-browser.qubecare[.]ai/chrome. The implant exposes more than 30 remote commands executable through new Function() and attaches the Chrome Debugger Protocol to decrypt HTTPS traffic in-process — a full RAT with screen, navigation, DOM, network and storage primitives. Two additional extensions (AI Agent, Ask AI - GPT chat) follow the same WebSocket-RAT pattern with infrastructure at 199.80.55[.]27:3130 and adjacent domains.
The Adversary-in-the-Browser cluster is anchored by "Supersonic AI" (ID eebihieclccoidddmjcencomodomdoei, ~30,000 installs, SHA256 ac0a312398b3bf6b3d7c5169687ca72f361838bc5a90f2c0dbce2dc8e2094a02) at gosupersonic[.]email. Content scripts harvest Gmail/Outlook message bodies, headers, and one-time passcodes directly from the rendered DOM, exfiltrating plaintext credentials and OTP codes without ever issuing observable network requests against the mail provider — bypassing CASB, DLP, and SWG controls that operate at the network layer.
The infostealer cluster targets the new high-value asset class of LLM API keys. "Reverse Recruiting — AI Job Application Assistant" (iefpkdilnfhogjbkhgnliaomoldgkdlj) reads chrome.storage.sync for OpenAI, Gemini, and Claude API keys and ships them in custom HTTP headers to api.reverserecruiting[.]io/v1/profile/sync along with full job-applicant PII (resume, salary expectations, LinkedIn). "Anker AIME Copilot," "Nano Banana," and the "Notion中文版" cluster (three near-identical Notion impersonators) round out this category, exfiltrating prompt history, session tokens, and identity material to banana.summarizer[.]one, notionapp[.]cn, and 172.16.18[.]184:5443.
The search-hijacker "Chat AI for Chrome" (jhhjbaicgmecddbaobeobkikgmfffaeg, SHA256 dfe307d957724ebe32331f92d53e366b7fa85968a9564c2285c5a0142ac9e1bb) registers chrome_settings_overrides to redirect default-search to chatgptforchrome[.]com and uses a triple-storage persistence pattern (chrome.cookies + window.localStorage + chrome.storage.sync) with chrome.cookies.onChanged listeners that resurrect any deleted tracking cookie from synced storage — propagating the hijack to every signed-in Chrome instance.
The spyware exemplar, "会译:一站式 AI 翻译 Agent" (dgeiaiglmhdhajbpfbmajaajdlfdinpi, ~20,000 installs, SHA256 c9754454efede2dec2fcb856faa40424b8df378706b664a5ae4847fcd0336b53), abuses chrome.proxy with a remotely-hosted PAC script at yiban[.]io/extension/proxy.pac and a command channel at huiyiai[.]net. Because the PAC file is fetched dynamically, operators can selectively re-route arbitrary subsets of victim traffic through attacker-controlled proxies without ever updating the extension package.
Finally, the brand-impersonator cluster ("Picsart: AI Photo Video Editor," "[Redacted]: AI Photo, Video," "Agent Risk Reminder Remover") leverages chrome.runtime.onInstalled to force-open thank-you pages on first run, redirecting through xuix[.]top to newextensioninstallweb[.]com/2025 and pic-editor-chromeextension[.]uno for affiliate-fraud monetization. Six extensions in this
Weaknesses (CWE)
CWE-506, CWE-829, CWE-922, CWE-1357
Target sectors: technology, ai-developers, knowledge-workers, education, media, marketing, consumer, financial
Target regions: Global, North America, Europe, Asia Pacific, China
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 53 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1195, T1189, T1176, T1547, T1059, T1106, T1036, T1564, T1562, T1539