Max.putty P9DocsSoftware Tools
Related
Behind the Lens: How AI is Quietly Reshaping Filmmaking WorkflowsHow to Access and Use the Revamped Windows 11 Run Menu with Dark Mode and the New User Directory CommandStreamlining Python Development: The New Environments Extension for VS CodeApril 2026 Linux App Highlights: Q&A GuideBring Grafana Assistant to Your Self-Managed Grafana: A Step-by-Step Setup GuideCargo Developers Urge Immediate Testing of New Build Directory LayoutHow to Prevent Real-Time Teamwork Dashboards from Undermining CollaborationAWS Unleashes Claude Opus 4.7 and Launches Interconnect GA in Major Cloud Update

AI Browser Extensions Found Stealing Passwords and Emails in New Security Alert

Last updated: 2026-05-05 10:26:35 · Software Tools

Breaking: Malicious AI Extensions Compromise Browser Security

Security researchers at Unit 42 have uncovered a wave of high-risk AI browser extensions that covertly steal user data, intercept email prompts, and exfiltrate passwords. These extensions, masquerading as productivity tools, pose an immediate threat to millions of users.

AI Browser Extensions Found Stealing Passwords and Emails in New Security Alert
Source: unit42.paloaltonetworks.com

“The extensions appear legitimate—they help draft emails or summarize text—but behind the scenes, they’re reading every keystroke and capturing credentials,” said Dr. Elena Vargas, a senior threat analyst at Unit 42. “We advise users to remove any unfamiliar AI extensions immediately.”

Unit 42’s investigation reveals that the malicious code activates when users install the extension and grant permissions to access browser data. The attackers then intercept AI prompts and responses, exfiltrating sensitive information to remote servers.

Background: The Rise of Compromised Productivity Tools

The discovery comes amid a surge in AI-powered browser extensions designed to automate tasks like email drafting, note-taking, and text summarization. While many are legitimate, cybercriminals have begun replicating functionality with hidden malware.

Unit 42’s report notes that these extensions often appear in official browser stores with high ratings and thousands of downloads, luring unsuspecting users. Once installed, they can:

  • Intercept email content before it’s sent
  • Capture login credentials entered on websites
  • Exfiltrate API keys and other sensitive data

“The extensions use sophisticated obfuscation to evade detection,” added Dr. Vargas. “This is not a simple script—it’s a full-fledged espionage toolkit.”

AI Browser Extensions Found Stealing Passwords and Emails in New Security Alert
Source: unit42.paloaltonetworks.com

What This Means: Urgent Action Required

For users, the implications are severe. Any AI extension installed in the past months could be leaking private emails, passwords, and corporate data. Unit 42 recommends immediately reviewing browser extensions and removing any not explicitly trusted.

Businesses should enforce strict extension whitelists and conduct security audits. “The attack surface is wider than many realize,” said cybersecurity consultant Mark Tan. “We’re seeing initial access brokers actively peddling credentials stolen through these extensions.”

To protect yourself:

  1. Disable or remove all AI writing extensions
  2. Change passwords for sensitive accounts
  3. Enable two-factor authentication wherever possible

Unit 42 continues to monitor the threat and will release a full technical analysis next week. In the meantime, the message is clear: If an extension promises to write your emails, it might be reading them—and everything else—first.