Beware of Malicious ChatGPT Chrome Extension Hijacking Facebook Accounts.

A fake ChatGPT Chrome browser extension, posing as OpenAI's ChatGPT service, has been removed from the official Web Store after harvesting Facebook session cookies and hijacking accounts. The extension was propagated through malicious sponsored Google search results and attracted over 9,000 installations before its removal. Once installed, it stealthily captured Facebook-related cookies and exfiltrated them to a remote server, allowing the threat actor to seize control of the Facebook account and disseminate extremist propaganda. This is the second fake ChatGPT Chrome browser extension to be discovered, highlighting the adaptability of cybercriminals to distribute malware and stage opportunistic attacks.
- Fake ChatGPT Chrome Browser Extension Caught Hijacking Facebook Accounts The Hacker News
- Facebook accounts hijacked by new malicious ChatGPT Chrome extension BleepingComputer
- Bogus ChatGPT extension steals Facebook cookies The Register
- "Chat GPT" scam extension stole Facebook data from up to 9000 users Laptop Mag
- This free Chrome extension brings a ChatGPT-powered assistant to your Google searches BGR
Reading Insights
0
16
1 min
vs 2 min read
73%
361 → 98 words
Want the full story? Read the original article
Read on The Hacker News