Global security desk · updated coverage of threats, exploits & breaches

Chrome Add-on Silently Steals Browser History and Logins

A newly documented malicious Chrome extension has been quietly harvesting browser history, saved passwords, and active session cookies from infected machines across multiple regions, including Australia. Researchers who analysed the add-on describe it as one of the most capable browser stealers seen so far this year, with a delivery chain that mimics legitimate AI productivity tools and infrastructure that overlaps with active infostealer marketplaces on the dark web.

The extension presents itself with a believable name and a clean user interface, then runs a data exfiltration routine in the background the moment the user accepts its permissions. Unlike a typical keylogger, it reaches into Chrome's internal databases and cookie jars, so the stolen data covers everything from autofill entries and recently visited URLs to session tokens for cloud platforms that keep users logged in for weeks at a time.

For users in Australia, the consequences land directly on services used every day. Banking logins for the major institutions, MyGov credentials, and session cookies for ATO portals all sit inside the same profile this extension quietly catalogues. The Australian Cyber Security Centre has repeatedly warned that credential theft drives a large share of incidents reported under the Notifiable Data Breaches scheme, and this campaign fits that pattern neatly.

Anatomy of the Rogue Add-on

The extension presents itself inside the Chrome Web Store with a polished landing page, a believable logo, and a short description that mimics legitimate AI writing tools. It asks for permissions that read like a wishlist for a stealer operator: reading and changing all data on every website, reading browser history, managing cookies, and access to local storage. Once accepted, a small JavaScript payload schedules an initial beacon to its backend and starts aggregating local browser artefacts before most users have noticed anything unusual.

Researchers who pulled the extension apart found it reaching into the SQLite databases Chrome uses to store login records, autofill entries, and recently visited URLs. Cookies tied to active sessions are pulled through the chrome.cookies.getAll API, which means even accounts protected by two-factor authentication can be replayed before the token expires. The harvested bundle is zipped, encoded, and uploaded to a hardcoded endpoint that rotates through disposable domains registered in the past few months.

The same family has been observed reaching into linked web applications. If the user is logged into a CRM, an internal wiki, or a customer portal, the extension will silently scrape content from open tabs and form fields while the user keeps working. That secondary layer of theft is what makes browser-resident malware more dangerous than a one-off keylogger: it walks away with whatever the user can see, and that often includes draft emails, internal documentation, and unredacted customer records.

Infection Chain and Distribution Tactics

Distribution leans on the same channels that have pushed infostealers for the past two years, with a clear local flavour. Researchers have observed the extension being promoted through sponsored social ads that mimic productivity software, through malvertising on file-conversion sites, and through search engine results poisoned with look-alike domains. The operator also buys traffic through push notification services, where users in Sydney and Melbourne browsing late at night on AEST schedules see a fake browser update prompt that redirects them to a landing page which auto-installs the package. Some infections have hit workers in Adelaide and Perth during their morning routine, when the lures mimic local news alerts about software patches.

A growing share of infections traces back to recruitment scams. LinkedIn-style messages targeting job seekers in Brisbane offer a short interview, then deliver a supposed onboarding form packaged as a Chrome add-on. This pattern has been seen across other malware families too, including fake listings that distribute infostealer payloads, as covered in a recent report on cybercriminals launch fake job postings to distill infostealers.

The infection chain rarely stops at one extension. Once the stealer phones home, the operators frequently push a second-stage payload through the same communication channel, often a clipboard hijacker that rewrites cryptocurrency wallet addresses, or a loader that pulls a more capable remote access trojan. The campaign also borrows playbooks from broader ransomware group claims attack on industrial control system manufacturer operators, who use stolen browser data as a stepping stone for lateral movement into corporate networks.

Australian Exposure and Targeted Services

The profile of data stolen from Australian users lines up closely with the platforms people rely on at work and at home. Banking sessions for the big four are an obvious target, but so are the smaller regional banks and credit unions whose customers often leave sessions active on shared machines. The harvested browser data includes account numbers, transaction histories, and in some cases statements downloaded from older sessions still cached locally, which gives fraudsters enough material to craft convincing vishing calls.

Government services are an even richer target. MyGov, the Australian Taxation Office portal, Centrelink, and the myPlace portal for Medicare all sit behind a single sign-on that uses cookies to keep users logged in for days. A stolen session cookie can be replayed from another country without triggering a new SMS or authenticator prompt if the user has ticked the "remember this device" box. State-level services used in New South Wales and Victoria, including Service NSW and Service Victoria web apps, fall into the same risk group, especially after-hours when staff resources for monitoring are thinner.

Beyond finance and government, the extension has been seen scraping retail logins. Woolworths Everyday Rewards, Coles online accounts, Bunnings PowerPass, and Telstra or Optus self-care logins all leak enough personal data to support identity fraud. With the 2022 Optus breach still fresh in the minds of many Australian consumers, the appetite for follow-on scams using stolen credentials remains high, and security teams at Australian retailers have raised their monitoring accordingly. Local analysts at the ACSC have also pointed out that browser-borne stealers are a leading initial vector in incidents reported through the Notifiable Data Breaches scheme over the past twelve months.

Comparing the Campaign Against Similar Browser Stealers

The table below compares this extension with other Chrome-targeted stealer activity tracked in the past year. It is not exhaustive, but it shows how the threat has converged on a common pattern, and where the current campaign pushes beyond what has been seen before.

Threat Data Targeted Distribution Notable Tactic Active Period
Productivity-AI Chrome Stealer (current) History, passwords, cookies, autofill, open tab content Sponsored ads, push traffic, fake job ads Uses chrome.cookies.getAll to bypass 2FA Ongoing
Rilide Loader Cookies, crypto wallet extensions, browser fingerprints Malvertising on PDF converter sites Hidden via obfuscated service worker 2024
Shampoo Chrome Extension Cookies, form data, screenshots SEO-poisoned install pages Captures tab screenshots on demand 2023 – 2024
Prophet Panda Stealer Passwords, history, payment autofill Bundled freeware installers Targets banking sessions first 2024
OAuth Ghost Add-on Session tokens for SaaS platforms Browser update lures Focuses on corporate cloud tokens 2024

All of these campaigns share the same weakness: they require the user to grant sweeping Chrome permissions that no legitimate productivity tool actually needs. The current campaign stands out for the speed at which it escalates from browser data theft to second-stage payload delivery, often within hours of the first beacon. That quick pivot is what makes the gap between a routine browser compromise and a full account takeover so much smaller than security advisories often suggest.

Detecting and Removing the Add-on

Removing the extension is straightforward once you know what to look for, but confirming the damage requires a few extra checks. Open chrome://extensions and review every installed add-on with the "can read and change all your data" permission. Anything unfamiliar, anything installed in the last few months without an obvious reason, or anything using a name that closely matches a known AI tool deserves a closer look. Toggle the developer mode toggle on the extensions page to see the extension ID, which is the same fingerprint researchers track across published reports.

After removing the extension, change every password it could have touched, starting with the email account that receives password resets for other services. Treat any session that was active during the infection window as compromised, and force a logout from those services through their account security pages. For Australian banking portals, call the institution's fraud line rather than relying on in-app password resets, because some banks will not flag suspicious activity unless the customer reports it directly. Rotate any API keys stored in browser password managers and revoke active sessions for cloud platforms such as Xero, MYOB, or the Atlassian suite if those are part of the workflow.

The next step is to wipe the residual state the extension may have left behind. Clear all cookies, the local site storage, and the browser cache, then run a second-opinion scan with a reputable on-demand scanner to catch any second-stage payload that may have been delivered during the active window. For organisations in Australia that fall under the Security of Critical Infrastructure obligations, the incident should be reported through the ACSC reporting portal, and any personal data breach should be assessed against the Notifiable Data Breaches threshold for OAIC notification.

Hardening the Browser Against Repeat

Prevention is far cheaper than response, and a handful of disciplined settings close the door on almost every browser stealer. Set Chrome to ask before installing any extension, disable the option to install add-ons from outside the Chrome Web Store, and review the extension list once a quarter with the same scepticism you would apply to unknown software on a laptop. For managed fleets, browser policies pushed through group policy can enforce the same posture across every workstation without depending on individual users to make the right call.

Where possible, switch from saving passwords in the browser to a dedicated password manager that does not expose credentials through a Chrome extension API. Use a hardware security key or a local authenticator app for two-factor verification on financial and government accounts, and avoid the "remember this device" option on shared or work-issued hardware. Segment personal and work browsers into separate profiles, or better still, separate browsers entirely, so a stolen cookie in one profile cannot pivot into the other.

For users who want a deeper audit, the published indicators for this campaign have been aggregated by independent trackers who maintain blocklists for similar add-ons and by security teams running community feeds. Pair those feeds with a DNS-level blocker and you cut off most of the operator infrastructure before the extension can phone home. Combined with a careful eye on the Chrome Web Store and a refusal to install anything that asks for blanket permissions, that posture will blunt the current campaign and the inevitable copycats that follow it.