HomeSecurityChrome extensions abuse links and steal access to ChatGPT

Chrome extensions abuse links and steal access to ChatGPT

Cybersecurity researchers have discovered malicious Google Chrome extensions that have the ability to hijack affiliate links, steal data, and collect ChatGPT authentication tokens.

See also: GhostPoster: Malicious extensions infected browsers for years

Chrome

One of the extensions in focus is Amazon Ads Blocker (ID: pnpchphmplpdimbllknjoiopmfphellj), which claims to be a tool for browsing Amazon without sponsored content. It was uploaded to the Chrome Web Store by a publisher named “10Xprofit” on January 19, 2026.

“ The extension does indeed block ads as advertised, but its main function is hidden: it automatically inserts the developer’s affiliate tag (10xprofit-20) into every Amazon product link and replaces existing affiliate codes from content creators ,” said Socket security researcher Kush Pandya .

Further analysis has determined that Amazon Ads Blocker is part of a larger set of 29 browser add-ons targeting various e-commerce platforms such as AliExpress, Amazon, Best Buy, Shein, Shopify , and Walmart.

While “Amazon Ads Blocker” offers the advertised functionality, it also embeds malicious code that scans all Amazon product URL patterns for any affiliate tag without requiring any user interaction, and replaces it with “10xprofit-20” (or “_c3pFXV63” for AliExpress). In cases where no tags are present, the attacker’s tag is added to each URL.

Socket also noted that the extension's listing page on the Chrome Web Store makes misleading disclosures, claiming that developers earn a "small commission" every time a user uses a coupon code to make a purchase.

See also: Malicious Chrome extensions target enterprise HR platforms

Chrome extensions abuse links and steal access to ChatGPT

Because the extensions look for existing tags and replace them, social media content creators who share Amazon product links with their own affiliate tags lose commissions when users who have the add-on installed click on those links.

The revelation comes as Symantec, which is owned by Broadcom, highlights four different extensions that have a combined user base exceeding 100,000 and are designed to steal data:

  • Good Tab (ID: glckmpfajbjppappjlnhhlofhdhlcgaj), which grants full clipboard access permissions to an external domain (“api.office123456[.]com”) to allow remote reading and writing to the clipboard.
  • Children Protection (ID: giecgobdmgdamgffeoankaipjkdjbfep), which implements functionality to collect cookies, insert ads, and execute arbitrary JavaScript by communicating with a remote server.
  • DPS Websafe (ID: bjoddpbfndnpeohkmpbjfhcppkhgobcg), which changes the default search to one under their control to record search terms entered by users and potentially direct them to malicious websites.
  • Stock Informer (ID: beifiidafjobphnbhbbgmgnndjolfcho), which is vulnerable to an old cross-site scripting (XSS) vulnerability in the Stockdio Historical Chart WordPress plugin (CVE-2020-28707, CVSS score: 6.1) that could allow a remote attacker to execute JavaScript code.

“While browser extensions can provide a wide range of useful tools to help us achieve more online, great care should be taken when choosing to install them, even when installed from trusted sources,” said researchers Yuanjing Guo and Tommy Dong.

See also: Chrome extensions have stolen conversations from ChatGPT and DeepSeek

Chrome extensions abuse links and steal access to ChatGPT

Rounding out the list of malicious extensions is another network of 16 add-ons (15 in the Chrome Web Store and one in the Microsoft Edge add-on marketplace) designed to intercept and steal ChatGPT authentication tokens by injecting a content script into chatgpt[.]com. In total, the extensions were downloaded about 900 times, according to LayerX.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS