Two Chrome extensions named "Phantom Shuttle" have been discovered masquerading as legitimate VPN or network speed testing tools while secretly intercepting user web traffic and exfiltrating sensitive credentials. Distributed through the Chrome Web Store since at least 2017, these extensions have deceived over 2,180 users, primarily targeting developers and foreign trade workers, by offering paid subscriptions and functional proxy services that create a false sense of legitimacy. The threat actor behind the scheme, using the email theknewone.com@gmail[.]com, published both variants, which operate identically despite different appearances.
The extensions employ a sophisticated credential injection mechanism, automatically inserting hardcoded proxy credentials (username: topfany, password: 963852wei) into every HTTP authentication request, thereby redirecting all browsing traffic through attacker-controlled proxy servers. This enables a persistent man-in-the-middle attack, with all user activity and credentials continuously exfiltrated to a command-and-control server at phantomshuttle[.]space. The malicious code is hidden within modified JavaScript libraries, specifically a tampered jquery-1.12.2.min.js, and the extensions maintain regular communication with the C2 server. Despite takedown requests, the extensions remain active on the Chrome Web Store as of late December 2025.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
As of BleepingComputer's reporting, the malicious Phantom Shuttle extensions were still accessible in the Chrome Web Store despite public disclosure and outreach to Google.
After identifying the malicious behavior, Socket submitted takedown requests to Google seeking removal of the Phantom Shuttle extensions from the Chrome Web Store.
Socket's Threat Research Team identified that the two Chrome extensions were intercepting traffic for more than 170 high-value domains, injecting hardcoded proxy credentials, and exfiltrating credentials and session data to attacker-controlled infrastructure. The research also tied the operation to long-running infrastructure, Chinese payment integrations, and more than 2,180 installs.
A second malicious Phantom Shuttle extension was published in 2023, expanding the same credential-theft and man-in-the-middle operation under the guise of a legitimate proxy or VPN service.
One of the malicious Phantom Shuttle Chrome extensions was available on the Chrome Web Store by at least 2017, posing as a VPN, proxy, or network testing tool while routing user traffic through attacker-controlled infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.