These malicious Google Chrome extensions have stolen data from over 170 websites – find out if you’re affected


  • Malicious Google Chrome Extensions “Phantom Shuttle” Secretly Rerouted Traffic Through Attacker-Controlled Proxies
  • Extensions targeted Chinese users and obtained credentials from 170 high-value domains
  • Google removed plugins; experts warn that browser add-ons remain a major security risk

Security researchers recently discovered that two extensions to the Google Chrome browser were redirecting valuable traffic through compromised proxies, thereby sharing sensitive information with malicious third parties.

Socket said it found two extensions in the Chrome Web Store, called ‘Phantom Shuttle’. On the surface, these were advertised as plugins for a proxy service that allows users to proxy traffic and test network speeds, and were mainly targeted at Chinese users such as foreign trade workers who need to test connectivity from different locations in the country.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top