{"id":183008,"date":"2026-01-30T08:42:00","date_gmt":"2026-01-30T13:42:00","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/01\/30\/researchers-uncover-chrome-extensions-abusing-affiliate-links-and-stealing-chatgpt-access\/"},"modified":"2026-01-30T10:00:14","modified_gmt":"2026-01-30T15:00:14","slug":"researchers-uncover-chrome-extensions-abusing-affiliate-links-and-stealing-chatgpt-access","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/01\/30\/researchers-uncover-chrome-extensions-abusing-affiliate-links-and-stealing-chatgpt-access\/","title":{"rendered":"Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/researchers-uncover-chrome-extensions.html\">Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/researchers-uncover-chrome-extensions.html\">https:\/\/thehackernews.com\/2026\/01\/researchers-uncover-chrome-extensions.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-01-30 08:42:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p>Author: <a href=\"\"><\/a><\/p>\n<p> Using an unordered list, summarize the following article with between 4 and 8 key points. <\/p>\n<p>Cybersecurity researchers have discovered malicious Google Chrome extensions that come with capabilities to hijack affiliate links, steal data, and collect OpenAI ChatGPT authentication tokens.<br \/>\nOne of the extensions in question is Amazon Ads Blocker (ID: pnpchphmplpdimbllknjoiopmfphellj), which claims to be a tool to browse Amazon without any sponsored content. It was uploaded to the Chrome Web Store by a publisher named &#8220;10Xprofit&#8221; on January 19, 2026.<br \/>\n&#8220;The extension does block ads as advertised, but its primary function is hidden: it automatically injects the developer&#8217;s affiliate tag (10xprofit-20) into every Amazon product link and replaces existing affiliate codes from content creators,&#8221; Socket security researcher Kush Pandya said.<br \/>\nFurther analysis has determined that Amazon Ads Blocker is part of a larger cluster of 29 browser add-ons that target several e-commerce platforms like AliExpress, Amazon, Best Buy, Shein, Shopify, and Walmart. The complete list is as follows &#8211;<\/p>\n<p>AliExpress Invoice Generator (FREE) &#8211; AliInvoice\u2122\ufe0f (10+ Templates) (ID: mabbblhhnmlckjbfppkopnccllieeocp)<br \/>\nAliExpress Price Tracker &#8211; Price History &#038; Alerts (ID: loiofaagnefbonjdjklhacdhfkolcfgi)<br \/>\nAliExpress Quick Currency &#038; Price Converter (ID: mcaglpclodnaiimhicpjemhcinjfnjce)<br \/>\nAliExpress Deals Countdown &#8211; Flash Sale Timer (ID: jmlgkeaofknfmnbpmlmadnfnfajdlehn)<br \/>\n10Xprofit &#8211; Amazon Seller Tools (FBA &#038; FBM) (ID: ahlnchhkedmjbdocaamkbmhppnligmoh)<br \/>\nAmazon Ads Blocker (ID: pnpchphmplpdimbllknjoiopmfphellj)<br \/>\nAmazon ASIN Lookup 10xprofit (ID: ljcgnobemekghgobhlplpehijemdgcgo)<br \/>\nAmazon Search Suggestion (ID: dnmfcojgjchpjcmjgpgonmhccibjopnb)<br \/>\nAmazon Product Scraper 10xprofit (ID: mnacfoefejolpobogooghoclppjcgfcm)<br \/>\nAmazon Quick Brand Search (ID: nigamacoibifjohkmepefofohfedblgg)<br \/>\nAmazon Stock Checker 999 (ID: johobikccpnmifjjpephegmfpipfbfme)<br \/>\nAmazon Price History Saver (ID: kppfbknppimnoociaomjcdgkebdmenkh)<br \/>\nAmazon ASIN Copy (ID: aohfjaadlbiifnnajpobdhokecjokhab)<br \/>\nAmazon Keyword Cloud Generator (ID: gfdbbmngalhmegpkejhidhgdpmehlmnd)<br \/>\nAmazon Image Downloader (ID: cpcojeeblggnjjgnpiicndnahfhjdobd)<br \/>\nAmazon Negative Review Hider (ID: hkkkipfcdagiocekjdhobgmlkhejjfoj)<br \/>\nAmazon Listing Score Checker (ID: jaojpdijbaolkhkifpgbjnhfbmckoojh)<br \/>\nAmazon Keyword Density Searcher (ID: ekomkpgkmieaaekmaldmaljljahehkoi)<br \/>\nAmazon Sticky Notes (ID: hkhmodcdjhcidbcncgmnknjppphcpgmh)<br \/>\nAmazon Result Numbering (ID: nipfdfkjnidadibpbflijepbllfkokac)<br \/>\nAmazon Profit Calculator Lite (ID: behckapcoohededfbgjgkgefgkpodeho)<br \/>\nAmazon Weight Converter (ID: dfnannaibdndmkienngjahldiofjbkmj)<br \/>\nAmazon BSR Fast View (ID: nhilffccdbcjcnoopblecppbhalagpaf)<br \/>\nAmazon Character Count &#038; Seller Tools (ID: goikoilmhcgfidolicnbgggdpckdcoam)<br \/>\nAmazon Global Price Checker (ID: mjcgfimemamogfmekphcfdehfkkbmldn)<br \/>\nBestBuy Search By Image (ID: nppjmiadmakeigiagilkfffplihgjlec)<br \/>\nSHEIN Search By Image (ID: mpgaodghdhmeljgogbeagpbhgdbfofgb)<br \/>\nShopify Search By Image (ID: gjlbbcimkbncedhofeknicfkhgaocohl)<br \/>\nWalmart Search By Image (ID: mcaihdkeijgfhnlfcdehniplmaapadgb)<\/p>\n<p>While &#8220;Amazon Ads Blocker&#8221; offers the advertised functionality, it also embeds malicious code that scans all Amazon product URL patterns for any affiliate tag without requiring any user interaction, and replaces it with &#8220;10xprofit-20&#8221; (or &#8220;_c3pFXV63&#8221; for AliExpress). In cases where there are no tags, the attacker&#8217;s tag is appended to each URL.<br \/>\nSocket also noted that the extension listing page on the Chrome Web Store makes misleading disclosures, claiming that the developers earn a &#8220;small commission&#8221; every time a user makes use of a coupon code to make a purchase. <\/p>\n<p>Affiliate links are widely used across social media and websites. They refer to URLs containing a specific ID that enables tracking of traffic and sales to a particular marketer. When a user clicks this link to buy the product, the affiliate earns a cut of the sale.<br \/>\nDue to the extensions searching for existing tags and replacing them, social media content creators who share Amazon product links with their own affiliate tags lose commissions when users who have installed the add-on click those links.<br \/>\nThis amounts to a violation of Chrome Web Store policies, as they require extensions using affiliate links to accurately divulge how the program works, require user action before each injection, and never replace existing affiliate codes.<br \/>\n&#8220;The disclosure describes a coupon\/deal extension with user-triggered reveals. The actual product is an ad blocker with automatic link modification,&#8221; Pandya explained. &#8220;This mismatch between disclosure and implementation creates false consent.&#8221;<br \/>\n&#8220;The extension also violates the Single Purpose policy by combining two unrelated functions (ad blocking and affiliate injection) that should be separate extensions.&#8221;<br \/>\nThe identified extensions have also been found to scrape product data and exfiltrate it to &#8220;app.10xprofit[.]io,&#8221; with those focusing on AliExpress serving bogus &#8220;LIMITED TIME DEAL&#8221; countdown timers on product pages to create a false sense of urgency and rush them into making purchases so as to earn commissions on affiliate links.<\/p>\n<p>&#8220;Extensions that combine unrelated functionality (ad blocking, price comparison, coupon finding) with affiliate injection should be treated as high-risk, particularly those with disclosures that don&#8217;t match the actual code behavior,&#8221; Socket said.<br \/>\nThe disclosure comes as Broadcom-owned Symantec flagged four different extensions that have a combined user base exceeding 100,000 users and are designed to steal data &#8211;<\/p>\n<p>Good Tab (ID: glckmpfajbjppappjlnhhlofhdhlcgaj), which grants full clipboard permissions to an external domain (&#8220;api.office123456[.]com&#8221;) to enable remote clipboard-read and clipboard-write permissions<br \/>\nChildren Protection (ID: giecgobdmgdamgffeoankaipjkdjbfep), which implements functionality to harvest cookies, inject ads, and execute arbitrary JavaScript by contacting a remote server<br \/>\nDPS Websafe (ID: bjoddpbfndnpeohkmpbjfhcppkhgobcg), which changes the default search to one under their control to capture search terms entered by users and potentially route them to malicious websites<br \/>\nStock Informer (ID: beifiidafjobphnbhbbgmgnndjolfcho), which is susceptible to a years-old cross-site (XSS) vulnerability in the Stockdio Historical Chart WordPress plugin (CVE-2020-28707, CVSS score: 6.1) that could allow a remote attacker to execute JavaScript code<\/p>\n<p>&#8220;While browser extensions can provide a wide range of handy tools to help us achieve more online, much care needs to be taken when choosing to install them, even when installing from trusted sources,&#8221; researchers Yuanjing Guo and Tommy Dong said.<br \/>\nRounding off the list of malicious extensions is another network of 16 add-ons (15 on the Chrome Web Store and one on the Microsoft Edge Add-ons marketplace) that are designed to intercept and steal ChatGPT authentication tokens by injecting a content script into chatgpt[.]com. Cumulatively, the extensions were downloaded about 900 times, according to LayerX.<br \/>\nThe extensions are assessed to be part of a coordinated campaign due to overlaps in source code, icons, branding, and descriptions &#8211;<\/p>\n<p>ChatGPT folder, voice download, prompt manager, free tools \u2013 ChatGPT Mods (ID: lmiigijnefpkjcenfbinhdpafehaddag)<br \/>\nChatGPT voice download, TTS download \u2013 ChatGPT Mods (ID: obdobankihdfckkbfnoglefmdgmblcld)<br \/>\nChatGPT pin chat, bookmark \u2013 ChatGPT Mods (ID: kefnabicobeigajdngijnnjmljehknjl)<br \/>\nChatGPT message navigator, history scroller \u2013 ChatGPT Mods (ID: ifjimhnbnbniiiaihphlclkpfikcdkab)<br \/>\nChatGPT model switch, save advanced model uses \u2013 ChatGPT Mods (ID: pfgbcfaiglkcoclichlojeaklcfboieh)<br \/>\nChatGPT export, Markdown, JSON, images \u2013 ChatGPT Mods (ID: hljdedgemmmkdalbnmnpoimdedckdkhm)<br \/>\nChatGPT Timestamp Display \u2013 ChatGPT Mods (ID: afjenpabhpfodjpncbiiahbknnghabdc)<br \/>\nChatGPT bulk delete, Chat manager \u2013 ChatGPT Mods (ID: gbcgjnbccjojicobfimcnfjddhpphaod)<br \/>\nChatGPT search history, locate specific messages \u2013 ChatGPT Mods (ID: ipjgfhcjeckaibnohigmbcaonfcjepmb)<br \/>\nChatGPT prompt optimization \u2013 ChatGPT Mods (ID: mmjmcfaejolfbenlplfoihnobnggljij)<br \/>\nCollapsed message \u2013 ChatGPT Mods (ID: lechagcebaneoafonkbfkljmbmaaoaec)<br \/>\nMulti-Profile Management &#038; Switching \u2013 ChatGPT Mods (ID: nhnfaiiobkpbenbbiblmgncgokeknnno)<br \/>\nSearch with ChatGPT \u2013 ChatGPT Mods (ID: hpcejjllhbalkcmdikecfngkepppoknd)<br \/>\nChatGPT Token counter \u2013 ChatGPT Mods (ID: hfdpdgblphooommgcjdnnmhpglleaafj)<br \/>\nChatGPT Prompt Manager, Folder, Library, Auto Send \u2013 ChatGPT Mods (ID: ioaeacncbhpmlkediaagefiegegknglc)<br \/>\nChatGPT Mods \u2013 Folder Voice Download &#038; More Free Tools (ID: jhohjhmbiakpgedidneeloaoloadlbdj)<\/p>\n<p>With artificial intelligence (AI)-related extensions becoming increasingly common in enterprise workflows, the development highlights an emerging attack surface where threat actors weaponize the trust associated with popular AI brands to deceive users into installing them.<br \/>\nBecause such tools often require elevated execution context within the browser and have access to sensitive data, seemingly harmless extensions can become a lucrative attack vector, permitting adversaries to obtain persistent access without the need for exploiting security flaws or resorting to other methods that may trigger security alarms.<\/p>\n<p>&#8220;Possession of such tokens provides account-level access equivalent to that of the user, including access to conversation history and metadata,&#8221; security researcher Natalie Zargarov said. &#8220;As a result, attackers can replicate the users&#8217; access credentials to ChatGPT and impersonate them, allowing them to access all of the user&#8217;s ChatGPT conversations, data, or code.&#8221;<br \/>\nBrowsers Become a Lucrative Attack Vector<br \/>\nThe findings also coincide with the emergence of a new malware-as-a-service toolkit called Stanley that&#8217;s being peddled on a Russian cybercrime forum for between $2,000 and $6,000, and allows crooks to generate malicious Chrome browser extensions that can be used to serve phishing pages within an HTML iframe element while still showing the legitimate URL in the address bar.<br \/>\nCustomers of the tool gain access to a C2 panel for managing victims, configuring spoofed redirects, and sending fake browser notifications. Those who are willing to spend $6,000 get a guarantee that any extension they create using the kit will pass Google&#8217;s vetting process for the Chrome Web Store.<br \/>\nThese extensions take the form of innocuous note-taking utilities to fly under the radar. But their malicious behavior is activated when the user navigates to a website of interest to the attacker, such as a bank, at which point a full-screen iframe containing the phishing page is overlaid, while leaving the browser&#8217;s URL bar intact. This visual deception creates a defensive blind spot that can dupe even vigilant users into entering their credentials or sensitive information on the page.<br \/>\nAs of January 27, 2025, the service appears to have vanished \u2013 likely prompted by the public disclosure \u2013 but it&#8217;s very much possible that it can resurface under a different name in the future.<br \/>\n&#8220;Stanley provides a turnkey website-spoofing operation disguised as a Chrome extension, with its premium tier promising guaranteed publication on the Chrome Web Store,&#8221; Varonis researcher Daniel Kelley noted earlier this week. &#8220;BYOD policies, SaaS-first environments, and remote work have made the browser the new endpoint. Attackers have noticed. Malicious browser extensions are now a primary attack vector.&#8221;<\/p>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access https:\/\/thehackernews.com\/2026\/01\/researchers-uncover-chrome-extensions.html Publish Date: 2026-01-30&#8230;<\/p>\n","protected":false},"author":1,"featured_media":183009,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi4xLoFpuzf6DbHF4Fy9WnEv4INmkiXkLiWxb9Pc7eqWDphv3Wcp57B38zLriR2xberjGDP_Xll60j1q8KmqpFTu9yfBIuyWilyHA97sm4-2CD_yqTOJubfYUKDp_-gkGHS-f-tcZYMk4N3sjwNzcy3GomBw-yVigT-MqY3J77PiGLVQyGK8JKHla5vykAd\/s1700-e365\/chrome.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[26,20,24,32,25,27],"class_list":["post-183008","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ai","tag-artificial-intelligence","tag-cybersecurity","tag-malware","tag-phishing","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/183008"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=183008"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/183008\/revisions"}],"predecessor-version":[{"id":183010,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/183008\/revisions\/183010"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/183009"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=183008"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=183008"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=183008"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}