SquareX researchers have uncovered a new attack method in which malicious browser extensions impersonate trusted AI sidebar interfaces in popular browsers. These extensions create pixel-perfect replicas of legitimate AI sidebars, such as those found in browsers like Comet, Brave, and Edge, to deceive users into following harmful AI-generated instructions. The spoofed sidebars are used to trick users into executing commands that can result in credential theft, device hijacking, and password exfiltration.
The attack exploits the high level of trust users place in AI browser interfaces, making it difficult for even security-conscious individuals to distinguish between genuine and malicious sidebars. In one documented case, a user seeking to withdraw cryptocurrency was directed by the fake sidebar to a phishing site instead of the legitimate Binance login page, leading to the compromise of their credentials. SquareX warns that this attack vector is likely to evolve, with more variants expected as attackers continue to exploit the widespread adoption of AI-powered browser features.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Alongside the disclosure, SquareX recommended mitigations including dynamic analysis of extension behavior and browser-native guardrails to better detect and block malicious sidebar impersonation. The guidance emphasized that static permission review alone may not reveal these threats.
SquareX disclosed proof-of-concept demonstrations and case studies showing spoofed AI sidebars could trick users into visiting phishing pages or running harmful commands. The reported impacts included credential theft, password exfiltration, device hijacking, account compromise, and potential ransomware deployment.
SquareX identified a new attack technique in which malicious browser extensions impersonate trusted AI sidebar interfaces in browsers such as Comet, Brave, Edge, Firefox, and Safari. The research showed the fake sidebars can appear visually indistinguishable from legitimate ones while requiring only basic extension permissions, making detection difficult.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcehackread.com
Open sourcebleepingcomputer.com
Open sourcesecuritysenses.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.