Google Chrome’s silent 4GB AI download problem

2026-05-06T20:51:52Zc9a7467e0a479d2c3e1cc6892551a88d3bce4602a2db32fa56f28106517e4286
active-exploitationai-modelbun-jscPanelcanvasdata-breachgoogle-appsheetgoogle-chromeinfostealerinstructurenwhstealerpaypalphishingprivacyrobloxscamsshinyhunterssupply-chainvulnerabilitieswhatsapp

What happened

Malwarebytes Labs reported multiple high-impact security stories: Google Chrome is silently downloading and reinstalling a 4GB AI model to users’ devices without consent, raising privacy, storage, and supply-chain concerns. Attackers are repurposing the Bun JavaScript runtime to package and distribute NWHStealer infostealer binaries. ShinyHunters claims a massive data breach of Instructure’s Canvas affecting ~275 million users (students and education providers). WhatsApp patched two vulnerabilities that could allow delivery of malicious or disguised files. An actively exploited cPanel/WHM flaw

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
c9a7467e0a479d2c3e1cc6892551a88d3bce4602a2db32fa56f28106517e4286
Enrichment time
2026-05-06T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Google Chrome’s silent 4GB AI download problem · Baitaphish