Skip to content
LayerXSecurity’s article

LayerXSecurity’s article

layerxsecurity.com • June 3, 2026

As generative AI tools like ChatGPT, Claude, Gemini, and Grok become part of everyday workflows, attackers are increasingly exploiting their popularity to distribute malicious browser extensions.

In this research, we uncovered a coordinated campaign of Chrome extensions posing as AI assistants for summarization, chat, writing, and Gmail assistance . While these tools appear legitimate on the surface, they hide a dangerous architecture: instead of implementing core functionality locally, they embed remote, server-controlled interfaces inside extension-controlled surfaces and act as privileged proxies, granting remote infrastructure access to sensitive browser capabilities.

Across 30 different Chrome extensions , published under different names and extension IDs and affecting over 260,000 users , we observed the same underlying codebase, permissions, and backend infrastructure .

Critically, because a significant portion of each extension’s functionality is delivered through remotely hosted components , their runtime behavior is determined by external server-side changes , rather than by code reviewed at install time in the Chrome Web Store.

The campaign consists of multiple Chrome extensions that appear independent, each with different names, branding, and extension IDs. In reality, all identified extensions the same internal structure, JavaScript logic, permissions, and backend infrastructure.

Across 30 extensions impacting more than 260,000 users , the activity represents a single coordinated operation rather than separate tools. Notably, several of the extensions in this campaign were Featured by the Chrome Web Store , increasing their perceived legitimacy and exposure.

This technique commonly known as extension spraying, is used to evade takedowns and reputation-based defenses. When one extension is removed, others remain available or are quickly re-published under new identities. Although the extensions impersonate different AI assistants (Claude, ChatGPT, Gemini, Grok, and generic “AI Gmail” tools), they all serve as entry points into the same backend-controlled system .

In this report we will analyze the AI Assistant (nlhpidbjmmffhoogcennoiopekbiglbp) extension.

Figure 1. Featured “Claude” Assistant

The extension renders a full-screen iframe pointing to a remote domain ( claude.tapnetic.pro ). This iframe overlays the current webpage and visually appears as the extension’s interface.

Because the iframe loads remote content:

When instructed by the iframe, the extension queries the active tab and invokes a content script that extracts readable article content using Mozilla’s Readability library. The extracted data includes titles, text content, excerpts, and site metadata.

Figure 3. Page Content Extraction

This information is then sent back to the remote iframe, meaning that a third-party server can receive structured representations of any page the user is viewing, including sensitive internal or authenticated pages.

The extension also supports message-triggered voice recognition using the Web Speech API. Upon request from the iframe, speech recognition is started and the resulting transcript is returned to the remote page.

While browser permissions may limit abuse in some cases, the presence of this capability demonstrates the broad scope of access granted to the remote controller.

The extension package includes explicit tracking pixel scripts that send install and uninstall events to a third-party analytics endpoint.

These mechanisms are commonly associated with:

Gmail Integration Cluster

A subset of the campaign, comprising 15 extensions, explicitly targets Gmail. Despite being published under different names and branding, and marketed as offering distinct capabilities not always related to email assistance, all of these extensions an identical Gmail integration codebase.

Each includes a dedicated Gmail-only content script that runs at document_start on mail.google.com , separate from the generic content script. This module injects extension-controlled UI elements into Gmail and maintains persistence using MutationObserver and periodic polling.

The Gmail integration reads visible email content directly from the DOM , repeatedly extracting message text via .textContent from Gmail’s conversation view.

This includes email thread content and, depending on state, draft or compose-related text.

When Gmail-related features such as AI-assisted replies or summaries are invoked, the extracted email content is passed into the extension’s logic and transmitted to third-party backend infrastructure controlled by the extension operator . As a result, email message text and related contextual data may be sent off-device, outside of Gmail’s security boundary, to remote servers.

All analyzed extensions communicate with infrastructure under the tapnetic[.]pro domain. While the domain hosts a publicly accessible website that appears legitimate at first glance, our analysis found that:

At the time of analysis, the site appeared to function primarily as cover infrastructure , lending legitimacy to the domain while the real activity occurs through extension-controlled subdomains.

Figure 5. Tapnetic.pro

Each extension communicates with a dedicated subdomain of tapnetic[.]pro , typically themed to match the impersonated AI product (e.g., Claude, ChatGPT, Gemini).

Figure 6. Tapnetic.pro subdomains - VirusTotal.com

This design provides several advantages to the operator:

Despite different subdomains, request structure, parameters, and server behavior are consistent across the campaign, indicating a single backend system.

We also observed active evasion of Chrome Web Store enforcement .

One extension in the campaign, fppbiomdkfbhgjjdmojlogeceejinadg , was removed from the Chrome Web Store on February 6, 2025 .

Less than two weeks later, an identical extension was published under a new ID and name:

The re-uploaded extension is a full copy of the removed one:

This behavior is consistent with extension spraying tactics , allowing operators to quickly restore distribution after takedowns while maintaining the same backend control.

The use of full-screen remote iframes combined with privileged API bridges transforms these extensions into general-purpose access brokers , capable of harvesting data, monitoring user behavior, and evolving silently over time. While framed as productivity tools, their architecture is incompatible with reasonable expectations of privacy and transparency.

As generative AI continues to gain popularity, defenders should expect similar campaigns to proliferate. Extensions that delegate core functionality to remote, mutable infrastructure should be treated not as convenience tools, but as potential surveillance platforms .

Security professionals, enterprise defenders, and browser developers should take the following actions:

Extracted Entities