Connect with us

Technology

300,000 Chrome users hit by fake AI extensions

Published

on

300,000 Chrome users hit by fake AI extensions

NEWYou can now listen to Fox News articles!

Your web browser may feel like a safe place, especially when you install helpful tools that promise to make your life easier. But security researchers have uncovered a dangerous campaign in which more than 300,000 people installed Chrome extensions pretending to be artificial intelligence (AI) assistants. Instead of helping, these fake tools secretly collect sensitive information like your emails, passwords and browsing activity.

They used familiar names like ChatGPT, Gemini and AI Assistant. If you use Chrome and have installed any AI-related extension, your personal information may already be exposed. Even worse, some of these malicious extensions are still available today, putting more people at risk without their knowing.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

More than 300,000 Chrome users installed fake AI extensions that secretly harvested sensitive data. (Kurt “CyberGuy” Knutsson)

Advertisement

What you need to know about fake AI extensions

Security researchers at browser security company LayerX discovered a large campaign involving 30 malicious Chrome extensions disguised as AI-powered assistants (via BleepingComputer). Together, these extensions were installed more than 300,000 times by unsuspecting users.

Some of the most popular extensions included names like AI Sidebar with 70,000 users, AI Assistant with 60,000 users, ChatGPT Translate with 30,000 users, and Google Gemini with 10,000 users. Another extension called Gemini AI Sidebar had 80,000 users before it was removed.

These extensions were distributed through the official Chrome Web Store, which made them appear legitimate and trustworthy. Even more concerning, researchers found that many of these extensions were connected to the same malicious server, showing they were part of a coordinated effort.

While some extensions have since been removed, others remain available. This means new users could still unknowingly install them and expose their personal data. Here’s the list of the affected extensions:

  • AI Assistant
  • Llama
  • Gemini AI Sidebar
  • AI Sidebar
  • ChatGPT Sidebar
  • Grok
  • Asking ChatGPT
  • ChatGBT
  • Chat Bot GPT
  • Grok Chatbot
  • Chat With Gemini
  • XAI
  • Google Gemini
  • Ask Gemini
  • AI Letter Generator
  • AI Message Generator
  • AI Translator
  • AI For Translation
  • AI Cover Letter Generator
  • AI Image Generator ChatGPT
  • Ai Wallpaper Generator
  • Ai Picture Generator
  • DeepSeek Download
  • AI Email Writer
  • Email Generator AI
  • DeepSeek Chat
  • ChatGPT Picture Generator
  • ChatGPT Translate
  • AI GPT
  • ChatGPT Translation
  • ChatGPT for Gmail

FAKE AI CHAT RESULTS ARE SPREADING DANGEROUS MAC MALWARE

These malicious tools were listed in the official Chrome Web Store, making them appear legitimate and trustworthy. (LayerX)

Advertisement

How the fake AI Chrome extension attack works

These fake extensions pretend to offer helpful AI features, such as translating text, summarizing emails, or acting as an AI assistant. But behind the scenes, they quietly monitor what you are doing online.

Once installed, the extension gains permission to view and interact with the websites you visit. This allows it to read the contents of web pages, including login screens where you enter your username and password.

In some cases, the extensions specifically targeted Gmail. They could read your email messages directly from your browser, including emails you received and even drafts you were still writing. This means attackers could access private conversations, financial information and sensitive personal details.

The extensions then sent this information to servers controlled by the attackers. Because they loaded content remotely, the attackers could change their behavior at any time without needing to update the extension.

Some versions could also activate voice features through your browser. This could potentially capture spoken conversations near your device and send transcripts back to the attackers.

Advertisement

If you installed one of these extensions, attackers may already have access to extremely sensitive information. This includes your email content, login credentials, browsing habits and possibly even voice recordings.

We reached out to Google for comment, and a spokesperson told CyberGuy that the company “can confirm that the extensions from this report have all been removed from the Google Web Store.”

BROWSER EXTENSION MALWARE INFECTED 8.8M USERS IN DARKSPECTRE ATTACK

Once installed, the extensions could read emails, capture passwords, monitor browsing activity and send the data to attacker-controlled servers. (Bildquelle/ullstein bild via Getty Images)

7 ways you can protect yourself from malicious Chrome extensions

If you have ever installed an AI-related Chrome extension, taking a few simple precautions now can help protect your accounts and prevent further damage.

Advertisement

1) Remove any suspicious or unused browser extensions

On a Windows PC or Mac, open Chrome and type chrome://extensions into the address bar. Review every extension listed. If you see anything unfamiliar, especially AI assistants you don’t remember installing, click “Remove” immediately. Malicious extensions depend on going unnoticed. Removing them stops further data collection and cuts off the attacker’s access to your information.

2) Change your passwords

If you installed any suspicious extension, assume your passwords may be compromised. Start by changing your email password first, since email controls access to most other accounts. Then update passwords for banking, shopping and social media accounts. This prevents attackers from using stolen credentials to break into your accounts.

3) Use a password manager to create and protect strong passwords

A password manager generates unique, complex passwords for each account and stores them securely. This prevents attackers from accessing multiple accounts if one password is stolen. Password managers also alert you if your login credentials appear in known data breaches, helping you respond quickly and protect your identity. Check out the best expert-reviewed password managers of 2026 at Cyberguy.com.

4) Install strong antivirus software and keep it active

Good antivirus software can detect malicious browser extensions, spyware, and other hidden threats. It scans your system for suspicious activity and blocks harmful programs before they can steal your information. This adds an important layer of protection that works continuously in the background to keep your device safe. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com.

5) Use an identity theft protection service

Identity theft protection services monitor your personal data, including email addresses, financial accounts, and Social Security numbers, for signs of misuse. If criminals try to open accounts or commit fraud using your information, you receive alerts quickly. Early detection allows you to act fast and limit financial and personal damage. See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com.

Advertisement

6) Keep your browser and computer fully updated

Software updates fix security vulnerabilities that attackers exploit. Enable automatic updates for Chrome and your operating system so you always have the latest protections. These updates strengthen your defenses against malicious extensions and prevent attackers from taking advantage of known weaknesses.

7) Use a personal data removal service

Personal data removal services scan data broker websites that collect and sell your personal information. They help remove your data from these sites, reducing what attackers can find and use against you. Less exposed information means fewer opportunities for criminals to target you with scams, identity theft or phishing attacks.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

Kurt’s key takeaway

Even tools designed to make your life easier can become tools for cybercriminals. Malicious extensions often hide behind trusted names and convincing features, making them difficult to spot. You can significantly reduce your risk by reviewing your browser extensions regularly, removing anything suspicious and using protective tools like password managers and strong antivirus software.

Advertisement

Have you checked your browser extensions recently? Let us know your thoughts by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Copyright 2026 CyberGuy.com. All rights reserved.

Advertisement

Related Article

Malicious browser extensions hit 4.3M users

Technology

Margaret Atwood says the problem with AI is ‘garbage in, garbage out’

Published

on

Margaret Atwood says the problem with AI is ‘garbage in, garbage out’

Maraget Atwood, the storied author of The Handmaid’s Tale and The Blind Assassin, was interviewed as part of the Babell Literary and Cultural Festival in Porto, Portugal. As it usually does at these things, the issue of AI came up, and Atwood didn’t mince words.

According to Deadline’s recap, Atwood said she’d used an AI chatbot exactly once, Anthropic’s Claude, and came away unimpressed. She was looking for information about the British detective series Father Brown and, well:

”Claude gave me the wrong answer, or it lied. Of course, it didn’t know it was lying because it’s not a human being; it’s a large language model… It had skimmed and sampled a lot of television reviews, but they never give away the ending in online criticism, so it was misled by the things it had read about the show.”

She didn’t have particularly kind words for the people who rely on AI either, calling them “opportunists” looking for the easy way out. But of course, as she pointed out, all LLMs are only as good as the data they’re fed, and putting your faith in a machine trained on scraped, previously published, and possibly out-of-date information isn’t the best idea.

“Human beings are not robots, but they are opportunists, so if there’s an easy way to cheat and it’s hard to detect, people will do it… But the thing about AI is that it’s garbage in, garbage out. Even people who use it for business reasons have to check it because it makes mistakes.”

Continue Reading

Technology

Empty envelopes in your mailbox? Do not scan that code

Published

on

Empty envelopes in your mailbox? Do not scan that code

NEWYou can now listen to Fox News articles!

A plain white envelope shows up in your mailbox. It is addressed to you. It may even have a tracking number. The sender’s name looks unfamiliar, but the delivery seems real. Then you open it. Nothing is inside. No note. No product. No explanation.

That would make anyone curious. And that is exactly what scammers may be counting on. Investigators and consumer protection groups have warned that empty envelopes and mystery packages can be tied to a scam known as brushing. In a more dangerous version, the package may include a QR code that tries to send you to a fake website or steal your personal information.

The bigger risk is what scammers hope you do next. If they can get you to scan a QR code, click a link, call a fake number or enter personal information, that strange envelope can turn into a much bigger problem.

Sign up for my FREE CyberGuy Report

Advertisement
  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join. 

QR CODE SCAMS RISE AS 73% OF AMERICANS SCAN WITHOUT CHECKING 

A mystery envelope may look harmless, but it can be a sign that your name and address are already being used in a brushing scam. (Kurt “CyberGuy” Knutsson)

 

What is the empty envelope scam?

The empty envelope scam is often connected to brushing. That is when a third-party seller sends a cheap item, or sometimes an empty envelope, to a real person’s address to make it look like a real order was delivered.

Once the package gets marked as delivered, a shady seller may use that delivery record to post a fake “verified buyer” review on an online marketplace. Those reviews can make junk products look more popular than they really are.

Recent reports describe people receiving small white padded envelopes from unfamiliar or possibly fake sender names. Some people get them more than once. Others receive cheap trinkets, packing material or nothing at all.

That may seem like a strange nuisance. But to me, the bigger concern is this: someone may already have your name and home address.

Advertisement

Why scammers send empty envelopes

Scammers do not need to send you anything valuable. They only need a tracking number that shows something arrived at a real home. Here is how the scam often works:

A scammer gets your name and address from a data broker, public record, old breach or online leak. Then they create a fake order using your information. Next, they mail a cheap item or an empty envelope to your home.

After the delivery gets marked as complete, the seller can make it appear that you bought the product. A fake positive review may then appear under your name or account details. That helps bad sellers boost ratings and fool real shoppers. It also shows that your personal information may already be floating around, where scammers can grab it.

THE ONE THING SCAMMERS CHECK BEFORE TARGETING YOU ONLINE

Scammers may use real deliveries, empty envelopes or cheap items to create fake “verified buyer” reviews online. (Kurt “CyberGuy” Knutsson)

Advertisement

The QR code twist makes this scam more dangerous

Some mystery packages now include a QR code. The message may sound harmless. It may say something like “scan to see who sent this gift” or “scan to verify delivery.” Do not scan it.

A QR code is a hidden link. You cannot easily see where it leads before your phone reads it. Scammers know curiosity is powerful, especially when a package arrives with your name on it.

That QR code may send you to a fake website that asks for your name, phone number, address, credit card, bank login or shopping account password. It may also try to trick you into entering a one-time verification code.

That is where the real financial risk begins. If you give scammers your login details or banking information, they may be able to take over accounts, make purchases or access payment apps.

What to do if you receive an empty envelope

If an envelope or package arrives and you did not order it, do not panic. Treat it as a warning sign and take a few smart steps.

Advertisement

1) Do not scan any QR code

Even if the card says you need to scan it to identify the sender, skip it. Go directly to the retailer, shipper or official website yourself.

2) Do not call mystery phone numbers

Scammers may include a fake customer service number or website inside the package. If you need to contact Amazon, Walmart, eBay, USPS, UPS or FedEx, type the official website into your browser or use the company’s official app.

3) Check your shopping accounts

Log in directly to your Amazon, Walmart, eBay, TikTok Shop and other shopping accounts. Look for orders you do not recognize, strange reviews, changed addresses or unfamiliar payment methods.

4) Change important passwords

Start with your email, shopping accounts and financial accounts. Use strong, unique passwords and consider using a password manager to create and store them safely. Do not reuse the same password across multiple sites. Check out the best expert-reviewed password managers of 2026 at Cyberguy.com

5) Turn on two-factor authentication

Two-factor authentication, also called 2FA, adds a second step to your login so a password alone isn’t enough. Use an authenticator app when possible. It gives you stronger protection than text messages and makes it harder for a scammer to get into your accounts.

Advertisement

6) Watch your bank and credit card statements

Look for small test charges, unfamiliar purchases, new subscriptions or withdrawals you did not make. Report anything suspicious to your bank right away.

7) Check your credit reports

If you think your identity may be at risk, review your credit reports. You can also consider a fraud alert or credit freeze with Equifax, Experian and TransUnion.

8) Report the package

Report suspicious packages to the U.S. Postal Inspection Service at uspis.gov/report. You can also file a scam report with the FBI’s Internet Crime Complaint Center at ic3.gov. If a retailer’s name appears on the label, report it directly through that retailer’s official site.

WARNING SIGNS YOUR MAIL HAS BEEN FRAUDULENTLY REDIRECTED

If an unexpected envelope includes a QR code, do not scan it. Go directly to the retailer, shipper or official website instead. (Kurt “CyberGuy” Knutsson)

Advertisement

What if you already scanned the QR code?

Scanning a QR code does not always mean your accounts are compromised. But if you entered information, downloaded an app or typed in a verification code, act quickly.

  • Close the browser window and stop using the site.
  • Do not enter any more personal or financial information.
  • Change the password for any account you entered and use a password manager to create and store a strong, unique replacement.
  • Turn on two-factor authentication (2FA).
  • Check your bank and credit card accounts for suspicious activity.
  • Contact your bank if you entered payment information.
  • Run a security scan on your phone or computer with a strong antivirus software.
  • Delete any app you installed from the QR code.
  • Report the incident to the FBI’s Internet Crime Complaint Center at ic3.gov and the FTC at reportfraud.ftc.gov.
  • If you entered your Social Security number, banking login or other sensitive information, consider freezing your credit.

Protect your phone from malicious links and QR codes

A good security tool can help block phishing websites, unsafe links and malicious downloads before they cause damage. We recommend using a strong antivirus software because it adds protection beyond basic virus scanning. It includes phishing protection, scam protection and web threat blocking for Windows, Mac, Android and iOS. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Reduce the personal data scammers can use

Brushing scams often start because your name, home address, phone number or other details are already online. Data brokers collect and sell this information. Scammers can use it to make their tricks feel more believable. A data removal service can help reduce your exposure by requesting that your personal information be removed from broker sites. We recommend using a good data removal service to help remove your personal information from data broker sites and reduce the amount of data scammers can use to target you. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

Kurt’s key takeaways

An empty envelope may look harmless, but it can be a sign that your personal information is already being misused. The most important move is to avoid anything inside the package that tries to pull you into another step. Do not scan QR codes from mystery packages. Do not call unknown numbers printed on cards. Do not enter personal information on a website you reached from a package you never ordered. Scammers are counting on curiosity. Slow down, go directly to official websites and secure your accounts before a strange envelope turns into a much bigger headache.

Have you received an empty envelope or mystery package you never ordered? Let us know by writing to us at Cyberguy.com

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Advertisement

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com.  All rights reserved.

Continue Reading

Technology

It’s the last day of Prime Day — here are over 140 great deals to choose from

Published

on

It’s the last day of Prime Day — here are over 140 great deals to choose from

We’ve arrived at the final day of Prime Day, which at this point should probably be called “Prime Week.” We’ve found discounts on all manner of gadgets, including TVs, smart home tech, chargers, headphones, and more. Some of the best deals have started selling out at some retailers, so if you’ve been craving a popular upgrade like the AirPods Max 2, time is running low.

The good news is that our team is still hard at work, and in addition to the deals that remain in stock, the retailers sometimes save up a few extras for the last day (like this Echo Spot that got a little cheaper). This roundup is our pride and joy; the culmination of over four days of deal hunting by our entire team. We’ve worked tirelessly for the last week and arrived at a list of over 120 discounted items (and growing) that we’re happy to share with you.

Of course, our Prime Day coverage spans every category The Verge staff touches, and is a great place to explore the full breadth of discounts we’re able to find on the stuff we’ve tested, regularly use, and love. We genuinely enjoy helping you save on cool tech and fun gadgets that are actually worth your hard-earned money, especially when everything is getting more expensive.

Smartwatch and wearable deals

Home theater and speaker deals

Advertisement

Update, June 26th: Struck some out of deals near the end of the sale.

Continue Reading
Advertisement

Trending