Malicious GenAI Chrome Extensions: Unpacking Data Exfiltration and Malicious Behaviours
Shresta B.Seetharam, Mohamed Nabeel, William Melicher

TL;DR
This study uncovers how malicious GenAI Chrome extensions exploit AI trends to exfiltrate data and deceive users, revealing evolving threats in the browser extension ecosystem through comprehensive detection and analysis.
Contribution
It introduces a multi-signal detection methodology to identify malicious extensions and provides an in-depth analysis of GenAI-related threats and attacker techniques.
Findings
Identified 154 previously undetected malicious extensions
Demonstrated attacker techniques like impersonation and query hijacking
Showed threat landscape evolution alongside GenAI adoption
Abstract
The rapid proliferation of AI and GenAI tools has extended to the Chrome Web Store. Cybercriminals are exploiting this trend, deploying malicious Chrome extensions posing as AI tools or impersonating popular GenAI models to target users. These extensions often appear legitimate while secretly exfiltrating sensitive data or redirecting users web traffic to attacker-controlled domains. To examine the impact of this trend on the browser extension ecosystem, we curated a dataset of 5,551 AI-themed extensions released over a nine-month period to the Chrome Web Store. Using a multi-signal detection methodology that combines manifest analysis, domain reputation, and runtime network behavior, supplemented with human review, we identified 154 previously undetected malicious Chrome extensions. Together with extensions known from public threat research disclosures, this resulted in a final set…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsWeb Application Security Vulnerabilities · Spam and Phishing Detection · Advanced Malware Detection Techniques
