These malicious Google Chrome extensions have stolen data from over 170 sites: find out if you’re affected


  • Malicious Google Chrome “Phantom Shuttle” extensions secretly redirected traffic through proxies controlled by attackers.
  • The extensions targeted Chinese users, harvesting credentials from 170 high-value domains
  • Google removed plugins; experts warn that browser add-ons remain a major security risk

Security researchers recently discovered that two Google Chrome browser extensions were redirecting valuable traffic through compromised proxies, sharing sensitive information with malicious third parties.

Socket said it found two extensions in the Chrome Web Store, named “Phantom Shuttle.” Ostensibly, these were presented as plugins for a proxy service, allowing users to proxy traffic and test network speeds, and were primarily aimed at Chinese users such as foreign trade workers who need to test connectivity from different locations around the country.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top