
Beware of Malicious ChatGPT Chrome Extension Hijacking Facebook Accounts.
A fake ChatGPT Chrome browser extension, posing as OpenAI's ChatGPT service, has been removed from the official Web Store after harvesting Facebook session cookies and hijacking accounts. The extension was propagated through malicious sponsored Google search results and attracted over 9,000 installations before its removal. Once installed, it stealthily captured Facebook-related cookies and exfiltrated them to a remote server, allowing the threat actor to seize control of the Facebook account and disseminate extremist propaganda. This is the second fake ChatGPT Chrome browser extension to be discovered, highlighting the adaptability of cybercriminals to distribute malware and stage opportunistic attacks.