The rapid proliferation of AI and GenAI tools has extended to the Chrome Web Store. Cybercriminals are exploiting this trend, deploying malicious Chrome extensions posing as AI tools or impersonating popular GenAI models to target users. These extensions often appear legitimate while secretly exfiltrating sensitive data or redirecting users web traffic to attacker-controlled domains. To examine the impact of this trend on the browser extension ecosystem, we curated a dataset of 5,551 AI-themed extensions released over a nine-month period to the Chrome Web Store. Using a multi-signal detection methodology that combines manifest analysis, domain reputation, and runtime network behavior, supplemented with human review, we identified 154 previously undetected malicious Chrome extensions. Together with extensions known from public threat research disclosures, this resulted in a final set of 341 malicious extensions for analysis. Of these, 29 were GenAI-related, forming the focus of our in-depth analysis and disclosure. We deconstruct representative GenAI cases, including Supersonic AI, DeepSeek AI | Free AI Assistant, and Perplexity Search, to illustrate attacker techniques such as Adversary-in-the-Browser, impersonation, bait-and-switch updates, query hijacking, and redirection. Our findings show that threat actors are leveraging GenAI trends and exploiting browser extension APIs and settings for malicious purposes. This demonstrates that the browser extension threat landscape is directly evolving alongside the rapid adoption of GenAI technologies.
翻译:人工智能与生成式AI工具的快速普及已延伸至Chrome Web Store。网络犯罪分子正利用这一趋势,部署伪装成AI工具或冒充热门生成式AI模型的恶意Chrome扩展以针对用户。这些扩展通常表面合法,实则暗中窃取敏感数据或将用户网络流量重定向至攻击者控制的域名。为评估该趋势对浏览器扩展生态系统的影响,我们收集了Chrome Web Store在九个月内发布的5,551个AI主题扩展数据集。通过结合清单分析、域名信誉与运行时网络行为的多信号检测方法,并辅以人工审查,我们识别出154个先前未被发现的恶意Chrome扩展。结合公开威胁研究报告已知的扩展,最终形成包含341个恶意扩展的分析集合。其中29个与生成式AI相关,成为我们深入分析与披露的重点。我们解构了包括Supersonic AI、DeepSeek AI | Free AI Assistant及Perplexity Search在内的典型生成式AI案例,以阐明攻击者采用的浏览器内攻击、身份伪装、诱导更新、查询劫持与重定向等技术。研究结果表明,威胁行为者正利用生成式AI趋势,并通过滥用浏览器扩展API与设置实现恶意目的。这证明浏览器扩展威胁态势正随着生成式AI技术的快速普及而同步演变。