BrowserGate: LinkedIn Tracks 6,000+ Browser Extensions on Users’ PCs

2026-04-05T20:51:41Z5fdc7bd49635dc08092cdd4ca2aeae232a83b35ff135c263fe797e5ee36be606
backdoorbrowser-extensionchatgpt-extensionciscocredential-harvestingdata-breachespionagegithubinfostealerlinkedinlitellmnodejsnorth-koreaprivacy-violationransomwaresalesforcesocial-engineeringsupply-chain-attacktrackingwhatsapp-attachment

What happened

This HackRead feed aggregates multiple active threats and privacy incidents: LinkedIn is accused of tracking 6,000+ browser extensions (BrowserGate); a North Korean cluster (UNC1069) is using fake LinkedIn/Slack profiles to target Node.js maintainers and spread malware; a malicious Chrome extension (‘ChatGPT Ad Blocker’) was harvesting ChatGPT conversations; researchers uncovered North Korean espionage using GitHub against South Korean firms; AI firm Mercor confirmed a LiteLLM-linked supply-chain breach with 4TB allegedly stolen; ShinyHunters claim theft of 3M+ Cisco records via Salesforce/AWS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
5fdc7bd49635dc08092cdd4ca2aeae232a83b35ff135c263fe797e5ee36be606
Enrichment time
2026-04-05T20:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · BrowserGate: LinkedIn Tracks 6,000+ Browser Extensions on Users’ PCs · Baitaphish