Security researchers reported a surge in malicious Chrome extensions abusing high-privilege browser permissions to steal credentials and hijack authenticated sessions. LayerX identified at least 16 ChatGPT-related extensions that mimic legitimate productivity tools and brands, then inject scripts into chatgpt.com to monitor outbound web requests and exfiltrate authorization details and session tokens to attacker-controlled infrastructure. With stolen tokens, attackers can impersonate victims’ ChatGPT sessions and potentially access connected data sources (e.g., integrations with Slack and GitHub), expanding impact beyond the AI service itself.
Separately, Varonis documented a malware-as-a-service browser-extension toolkit dubbed Stanley being sold on Russian-language cybercrime forums, marketed to enable large-scale credential theft by showing a phishing site while the URL bar continues to display the legitimate domain. The toolkit uses a web-based control panel to configure per-victim “source” (legitimate) and “target” (phishing) URLs, then overlays a full-screen iframe to spoof the destination site; the seller also claims “guaranteed” placement in the Chrome Web Store, increasing the likelihood of user installation and enterprise exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Varonis publicly described Stanley as a toolkit for building malicious Chrome extensions that overlay attacker-controlled phishing pages on legitimate sites while the browser continues to show the real URL. The researchers also detailed its web-based control panel, IP-based victim targeting, frequent C2 polling, and abuse of browser notifications.
LayerX Research disclosed a coordinated campaign of 16 browser extensions masquerading as ChatGPT productivity tools that steal ChatGPT session tokens. The extensions inject scripts into chatgpt.com, hook outbound requests, and exfiltrate authorization data to attacker-controlled infrastructure; about 900 installations were observed across Chrome and Edge listings.
After identifying Stanley and its malicious "Notely" browser-extension activity, Varonis reported the campaign to Google. The report said the main command-and-control server was later taken offline, although the extension remained active for some time afterward.
Varonis reported that the malware-as-a-service browser attack toolkit "Stanley" first appeared on a Russian-language cybercrime forum on January 12, 2026. It was advertised under the alias "Стэнли" with tiers priced from $2,000 to $6,000, including a premium option claiming Chrome Web Store publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcescworld.com
Open sourcedarkreading.com
Open sourcecyberscoop.com
Open sourcelayerxsecurity.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.