These malicious Google Chrome extensions have stolen data from more than 170 sites: find out if you are affected



  • “Phantom Shuttle” malicious Google Chrome extensions secretly redirect traffic through attacker-controlled proxy servers
  • The extensions targeted Chinese users and collected credentials from 170 high-value domains.
  • Google removed the plugins; Experts warn that browser add-ons remain a major security risk.

Security researchers recently discovered that two extensions for the Google Chrome browser were redirecting valuable traffic through compromised proxy servers and therefore sharing sensitive information with malicious third parties.

Socket said it found two extensions in the Chrome Web Store, called ‘Phantom Shuttle’. At first glance, these were advertised as add-ons to a proxy service, allowing users to proxy traffic and test network speeds, and were primarily aimed at Chinese users, such as foreign trade workers who need to test connectivity from different locations in the country.



Leave a Comment

Your email address will not be published. Required fields are marked *