Connect with us

Technology

Malicious Chrome extensions caught stealing sensitive data

Published

on

Malicious Chrome extensions caught stealing sensitive data

NEWYou can now listen to Fox News articles!

Chrome extensions are supposed to make your browser more useful, but they’ve quietly become one of the easiest ways for attackers to spy on what you do online. Security researchers recently uncovered two Chrome extensions that have been doing exactly that for years.

These extensions looked like harmless proxy tools, but behind the scenes, they were hijacking traffic and stealing sensitive data from users who trusted them. What makes this case worse is where these extensions were found. Both were listed on Chrome’s official extension marketplace.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

FAKE AI CHAT RESULTS ARE SPREADING DANGEROUS MAC MALWARE

Advertisement

Security researchers uncovered malicious Chrome extensions that quietly routed users’ web traffic through attacker-controlled servers to steal sensitive data. (Gokhan Balci/Anadolu Agency/Getty Images)

Malicious Chrome extensions hiding in plain sight

Researchers at Socket discovered two Chrome extensions using the same name, “Phantom Shuttle,” that were posing as tools for proxy routing and network speed testing (via Bleeping Computer). According to the researchers, the extensions have been active since at least 2017.

Both extensions were published under the same developer name and marketed toward foreign trade workers who need to test internet connectivity from different regions. They were sold as subscription-based tools, with prices ranging from roughly $1.40 to $13.60.

At a glance, everything looked normal. The descriptions matched the functionality. The pricing seemed reasonable. The problem was what the extensions were doing after installation.

How Phantom Shuttle steals your data

Socket researchers say Phantom Shuttle routes all your web traffic through proxy servers controlled by the attacker. Those proxies use hardcoded credentials embedded directly into the extension’s code. To avoid detection, the malicious logic is hidden inside what appears to be a legitimate jQuery library.

Advertisement

The attackers didn’t just leave credentials sitting in plain text. The extensions hide them using a custom character-index encoding scheme. Once active, the extension listens to web traffic and intercepts HTTP authentication challenges on any site you visit.

To make sure traffic always flows through their infrastructure, the extensions dynamically reconfigure Chrome’s proxy settings using an auto-configuration script. This forces your browser to route requests exactly where the attacker wants them.

In its default “smarty” mode, Phantom Shuttle routes traffic from more than 170 high-value domains through its proxy network. That list includes developer platforms, cloud service dashboards, social media sites and adult content portals. Local networks and the attacker’s own command-and-control domain are excluded, likely to avoid breaking things or raising suspicion.

While acting as a man-in-the-middle, the extension can capture anything you submit through web forms. That includes usernames, passwords, card details, personal information, session cookies from HTTP headers and API tokens pulled directly from network requests.

CyberGuy contacted Google about the extensions, and a spokesperson confirmed that both have been removed from the Chrome Web Store.

Advertisement

10 SIMPLE CYBERSECURITY RESOLUTIONS FOR A SAFER 2026

Two Chrome extensions posing as proxy tools were found spying on users for years while listed on Google’s official Chrome Web Store. (Yui Mok/PA Images via Getty Images)

How to review the extensions installed in your browser (Chrome)

The step-by-step instructions below apply to Windows PCs, Macs and Chromebooks. In other words, desktop Chrome. Chrome extensions cannot be fully reviewed or removed from the mobile app.

Step 1: Open your extensions list

  • Open Chrome on your computer.
  • Click the three-dot menu in the top-right corner.
  • Select Extensions
  • Then click Manage Extensions.

You can also type this directly into the address bar and press Enter:
chrome://extensions

Step 2: Look for anything you do not recognize

Go through every extension listed and ask yourself:

  • Do I remember installing this?
  • Do I still use it?
  • Do I know what it actually does?

If the answer is no to any of these, take a closer look.

Step 3: Review permissions and access

Click Details on any extension you are unsure about. Pay attention to:

Advertisement
  • Permissions, especially anything that can read or change data on websites you visit
  • Site access, such as extensions that run on all sites
  • Background access, which allows the extension to stay active even when not in use

Proxy tools, VPNs, downloaders and network-related extensions deserve extra scrutiny.

Step 4: Disable suspicious extensions first

If something feels off, toggle the extension off. This immediately stops it from running without deleting it. If everything still works as expected, the extension was likely not essential.

Step 5: Remove extensions you no longer need

To fully remove an extension:

  • Click Remove
  • Confirm when prompted

Unused extensions are a common target for abuse and should be cleaned out regularly.

Step 6: Restart Chrome

Close and reopen Chrome after making changes. This ensures disabled or removed extensions are no longer active.

MICROSOFT TYPOSQUATTING SCAM SWAPS LETTERS TO STEAL LOGINS

Cybersecurity experts warn that trusted browser extensions can become powerful surveillance tools once installed. (Gabby Jones/Bloomberg via Getty Images)

Advertisement

6 steps you can take to stay safe from malicious Chrome extensions

You can’t control what slips through app store reviews, but you can reduce your risk by changing how you install and manage extensions.

1) Install extensions only when absolutely necessary

Every extension increases your attack surface. If you don’t genuinely need it, don’t install it. Convenience extensions often come with far more permissions than they deserve.

2) Check the publisher carefully

Reputable developers usually have a history, a website and multiple well-known extensions. Be cautious with tools from unknown publishers, especially those offering network or proxy features.

3) Read multiple user reviews, not just ratings

Star ratings can be faked or manipulated. Look for detailed reviews that mention long-term use. Watch out for sudden waves of generic praise.

4) Review permissions before clicking install

If an extension asks to “read and change all data on websites you visit,” take that seriously. Proxy tools and network extensions can see everything you do.

Advertisement

5) Use a password manager

A password manager won’t stop a malicious extension from spying on traffic, but it can limit damage. Unique passwords mean stolen credentials can’t unlock multiple accounts. Many managers also refuse to autofill on suspicious pages.

Next, see if your email has been exposed in past breaches. Our #1 password manager (see Cyberguy.com/Passwords) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.

Check out the best expert-reviewed password managers of 2025 at Cyberguy.com.

6) Install strong antivirus software

Strong antivirus software can flag suspicious network activity, proxy abuse and unauthorized changes to browser settings. This adds a layer of defense beyond Chrome’s own protections.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Advertisement

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Kurt’s key takeaway

This attack doesn’t rely on phishing emails or fake websites. It works because the extension itself becomes part of your browser. Once installed, it sees nearly everything you do online. Extensions like Phantom Shuttle are dangerous because they blend real functionality with malicious behavior. The extensions deliver the proxy service they promise, which lowers suspicion, while quietly routing user data through attacker-controlled servers.

When was the last time you reviewed the extensions installed in your browser? Let us know by writing to us at Cyberguy.com.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

Copyright 2025 CyberGuy.com. All rights reserved.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Tenways’ compact e-bike twists and folds to go flat

Published

on

Tenways’ compact e-bike twists and folds to go flat

Tenways just launched its new CGO Compact electric bike in Europe that’s designed to fit into tight spaces like car trunks, apartment hallways, and train compartments.

To achieve this, the CGO Compact is fitted with small 20-inch wheels, folding pedals, and a handlebar fitted with a twistable stem to create a slim, wall-hugging profile. The adjustable steering column and low-step through frame also make it suitable for a wide range of rider heights, so it could be a good shareable e-bike for families. And its MIK HD rear carrier system is good for hauling up to 27kg (almost 60 pounds) around town, with mounting points for additional accessories like a crate or child seat.

Tenways might not be a household name globally, but the Chinese e-bike company headquartered in the Netherlands is making a name for itself in Europe thanks to aggressive pricing, sleek designs, and over 1,500 shops and service centers. And while the CGO Compact’s €1,999 (about $2,365) price tag isn’t cheap, it’s well below the €2,681 average for European e-bikes.

The company does sell e-bikes in the US, but the CGO Compact is only for sale in Europe as of today. It features a 250W rear-hub motor connected to a Gates Carbon belt drive for maintenance-free propulsion. It promises a range of up to 100km from its 500Wh removable battery, but its single-speed drivetrain produces only 45Nm of torque so it’s best suited for relatively flat cities. If your commute does stray from asphalt then the suspension seat post should help absorb bumps. There’s also an integrated torque sensor to ensure the smooth delivery of pedal-assisted power, and Tektro hydraulic disc brakes should keep any sudden stops under control.

The CGO Compact lives up to its name regarding size, but it’s not all that lightweight. Stripped down it weighs 19.8kg (almost 44 pounds), or 22.1kg (almost 49 pounds) with all the accessories you’ll want in wet urban environments. That makes it heavier than many full-sized e-bikes, even from Tenways, and less versatile than the excellent 20-inch Brompton G foldable which also weighs less but costs more than twice as much.

Advertisement
Continue Reading

Technology

Fox News AI Newsletter: Trump activates ‘tech force’

Published

on

Fox News AI Newsletter: Trump activates ‘tech force’

NEWYou can now listen to Fox News articles!

Welcome to Fox News’ Artificial Intelligence newsletter with the latest AI technology advancements.

IN TODAY’S NEWSLETTER:

Inside Trump administration’s AI tech force designed to modernize government
Elon Musk slams Anthropic AI models as ‘misanthropic’ and ‘evil’ in scathing social media post
AI power players pour cash into competitive primaries as 2026 midterms heat up

‘TECH FORCE’: Inside Trump administration’s AI initiative designed to modernize government – FOX Business reports on the Trump administration’s latest initiative to overhaul federal efficiency, detailing an internal AI “tech force” tasked with modernizing antiquated government systems and streamlining operations.

Advertisement

TECH ALLIANCE: War Department to partner with OpenAI to integrate ChatGPT, GenAI for military use – The Department of Defense is reportedly strengthening its technological arsenal through a strategic partnership with OpenAI, aiming to integrate ChatGPT and generative AI capabilities into military operations to maintain a strategic edge.

SCATHING POST: Elon Musk slams Anthropic AI models as ‘misanthropic’ and ‘evil’ – Tech billionaire Elon Musk took to social media to unleash a scathing attack on rival AI firm Anthropic, characterizing their models as “misanthropic” and “evil” in a post that highlights the intensifying ideological rift within Silicon Valley.

Elon Musk, chief executive officer of Tesla Inc., during the US-Saudi Investment Forum at the Kennedy Center in Washington, DC, US, on Wednesday, Nov. 19, 2025 (Stefani Reynolds/Bloomberg via Getty Images)

POWER PLAYERS: AI execs pour cash into competitive primaries as 2026 midterms heat up – With the 2026 midterm elections on the horizon, deep-pocketed investors and executives from the artificial intelligence sector are pouring cash into competitive primaries, hoping to shape the regulatory landscape for the booming technology.

OPINION: AI raises the stakes for national security — here is how to get it right – In this opinion piece, OpenAI’s Chris Lehane argues that the rapid advancement of artificial intelligence has dramatically raised the stakes for American national security, outlining a strategic framework to ensure the U.S. maintains its dominance without compromising safety.

Advertisement

OPINION: The 2028 election will be a referendum on our future in an AI-dominated world – As technology accelerates, this op-ed contends that the 2028 presidential election will serve as a critical referendum on humanity’s future, forcing voters to decide how the nation should navigate an increasingly AI-dominated world.

Children forming deep emotional connections with AI companions is raising questions among parents. (StockPlanets/Getty Images)

BATTLE FOR DOMINANCE: AI wars begin in new Super Bowl commercials – The battle for artificial intelligence dominance has moved to the advertising stage, as tech giants unleash a wave of new Super Bowl commercials designed to capture the public imagination and assert their position in the “AI wars.”

BOT TO THE FUTURE: Humanoid robots are getting smaller, safer and closer to home – Recent advancements in robotics are making humanoid machines smaller, safer, and more viable for domestic use, suggesting that a future where robots assist with daily household tasks is getting closer to reality.

MOYA’S DEBUT: ‘Warm-skinned’ AI robot with camera eyes is seriously creepy – A new development in robotics featuring “warm skin” and camera eyes has sparked a mix of fascination and unease, with many observers describing the lifelike yet artificial creation as “seriously creepy.”

Advertisement

Moya’s humanlike appearance is intentional, from her warm skin to subtle facial details designed to feel familiar rather than mechanical.   (DroidUp)

DIGITAL DANGER: AI companions are reshaping teen emotional bonds – A growing trend of teenagers forming deep emotional connections with AI companions is raising questions among parents and psychologists about the long-term impact of synthetic relationships on social development and mental health.

Subscribe now to get the Fox News Artificial Intelligence Newsletter in your inbox.

FOLLOW FOX NEWS ON SOCIAL MEDIA

Facebook
Instagram
YouTube
X
LinkedIn

SIGN UP FOR OUR OTHER NEWSLETTERS

Advertisement

Fox News First
Fox News Opinion
Fox News Lifestyle
Fox News Health

DOWNLOAD OUR APPS

Fox News
Fox Business
Fox Weather
Fox Sports
Tubi

WATCH FOX NEWS ONLINE

Fox News Go

Advertisement

STREAM FOX NATION

Fox Nation

Stay up to date on the latest AI technology advancements and learn about the challenges and opportunities AI presents now and for the future with Fox News here.

 

Advertisement

Continue Reading

Technology

A surprise God of War prequel is out on the PS5 right now

Published

on

A surprise God of War prequel is out on the PS5 right now

To close out its February 2026 State of Play presentation, Sony revealed God of War Sons of Sparta, a new prequel 2D side scroller in the God of War franchise, and announced that it’s out right now on PlayStation 5.

God of War Sons of Sparta is a 2D action platformer with a canon story set in Kratos’ youth during his harsh training at the Agoge alongside his brother Deimos,” Sony says. Over the course of the game, Kratos will “learn deadly skills using his spear and shield, as well as harness powerful divine artifacts known as the Gifts of Olympus to take on a wide array of foes.”

Sony’s Santa Monica Studio collaborated on the game with Mega Cat Studios. It costs $29.99, with a Digital Deluxe version available for $39.99.

Sony also announced that it’s working on a remake of the original God of War trilogy, with TC Carson set to return as the voice of Kratos. However, the project is “still very early in development, so we ask for your patience as it will be a while before anything else can be shared,” according to Sony. “When we can come back with an update, we aim to make it a big one!”

Continue Reading

Trending