Fake ChatGPT Ad Blocker Chrome Extension Caught Spying on Users
2026-04-03T20:52:08Z•0cffd031371b7b8bfde5096dbf133e6991ba1e9e39292e21830bb881082d2bce
awsbrowser-malwarechatgptchrome-extensionciscodarksworddata-breachespionagegithub-abuseinfostealerios-18ios-patchliteLLMmalicious-extensionmercornorth-korean-actorsransomwaresalesforcesecurity-patchshinyhuntersstorm-infostealersupply-chain-attackvbs-backdoorwhatsapp-attachmentsyurei-ransomware
What happened
Multiple high-impact cybersecurity incidents reported: a malicious Chrome extension (“ChatGPT Ad Blocker”) was harvesting ChatGPT conversations; FortiGuard researchers attribute a high-severity espionage campaign abusing GitHub to North Korean actors targeting South Korean firms; AI firm Mercor confirmed a LiteLLM-related supply-chain breach with alleged 4TB exfiltration; ShinyHunters claim theft of 3M+ Cisco records via Salesforce/AWS; Microsoft warned of WhatsApp attachments delivering a VBS backdoor on Windows. Additional coverage includes Yurei ransomware activity, the Storm infostealer (b
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 0cffd031371b7b8bfde5096dbf133e6991ba1e9e39292e21830bb881082d2bce
- Enrichment time
- 2026-04-03T20:52:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.