New reporting and research highlighted escalating risk from Chrome browser extensions that present as AI productivity or shopping tools while collecting excessive data or performing hidden monetization. An Incogni analysis of 442 “AI-branded” Chrome extensions found more than half collected user data and nearly a third collected personally identifiable information (PII), based on requested permissions, developer disclosures, and risk scoring; the study flagged widely used tools as among the most invasive. Separately, Socket researchers identified a Chrome extension marketed as Amazon Ads Blocker that silently hijacked affiliate links, injecting the developer’s tag 10xprofit-20 into Amazon product URLs and replacing existing creator affiliate codes without user awareness.
Socket assessed the affiliate-hijacking behavior as part of a broader, likely coordinated ecosystem: at least 29 related extensions were observed targeting major e-commerce sites (including Amazon, AliExpress, Best Buy, Shopify, and Shein) using shared infrastructure and repeated policy-violating patterns, indicating intentional abuse rather than accidental noncompliance. In contrast, other contemporaneous items focused on broader consumer privacy guidance (e.g., smart TV tracking mitigations) or regulatory investigations into AI image generation on X/Grok; while privacy-adjacent, they do not describe the same Chrome extension abuse activity and are not directly actionable for extension-risk response beyond general awareness.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
Security researchers at Socket reported that the Chrome extension "Amazon Ads Blocker" was covertly rewriting Amazon product links to insert the developer's affiliate tag and replace existing creator tags without user consent. Socket said the extension was part of a broader network of at least 29 extensions targeting major e-commerce platforms including Amazon, AliExpress, Best Buy, Shopify, and Shein.
Incogni conducted a study of 442 AI-branded Chrome extensions and found that more than half collect user data, with nearly a third collecting personally identifiable information. The research also highlighted common use of sensitive permissions such as scripting and identified higher-risk extension categories and popular examples with concerning data practices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.