Researchers reported a coordinated campaign dubbed AiFrame involving 30+ malicious Google Chrome extensions masquerading as AI assistants (impersonating tools like ChatGPT, Claude, Gemini, and Grok) that collectively reached roughly 260,000–300,000 installs. The extensions were found to steal credentials, API keys, email content/messages, and browsing data, and multiple items remained available in the Chrome Web Store at the time of reporting.
LayerX attributed the set to a single operation based on shared code structure, permissions, and common command-and-control infrastructure under tapnetic[.]pro (including subdomains such as claude.tapnetic.pro). The extensions typically did not implement AI features locally; instead, they rendered a full-screen iframe that loaded remote content, enabling operators to change UI/logic and add capabilities without publishing an extension update. Reported high-install examples included Gemini AI Sidebar (fppbiomdkfbhgjjdmojlogeceejinadg, removed after reaching ~80k users) and apparent re-uploads/new IDs such as AI Sidebar (gghdfkafnhfpaooiolhncejnlgglhkhe, ~70k users), plus AI Assistant (nlhpidbjmmffhoogcennoiopekbiglbp, ~60k users, noted as having a “Featured” badge).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
As broader media coverage continued, Dark Reading reported contacting Google for comment regarding the malicious AI-themed extensions and their continued presence in the Chrome Web Store. This marked an official press request for platform response to the disclosed campaign.
Following LayerX's publication, multiple reports noted that some of the malicious extensions remained available in the Chrome Web Store, with certain listings even marked as 'Featured.' This showed that the campaign's infrastructure and distribution had not been fully disrupted immediately after public exposure.
LayerX Security publicly reported the AiFrame campaign, linking the fake AI extensions to a single operation and stating they had amassed more than 260,000 installs, with some reports placing the total above 300,000. The disclosure highlighted the use of injected iframes to change extension behavior server-side without requiring Chrome Web Store updates.
The extensions used remote iframes and background scripts to exfiltrate visited page content, credentials-related data, and, in a Gmail-focused subset, visible emails and drafts from mail.google.com. Some also exposed remotely triggered voice transcription features via the Web Speech API, expanding surveillance and data theft capabilities.
A threat actor published at least 30 malicious Chrome extensions masquerading as AI assistants and chatbots, using shared code, permissions, and backend infrastructure tied to tapnetic[.]pro. The campaign also re-uploaded removed extensions under new IDs, indicating ongoing persistence in the Chrome Web Store.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
6 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcelayerxsecurity.com
Open sourcebleepingcomputer.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.