TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

Experts Sound Alarm Over “Prompt Poaching” Browser Extensions

2026-03-25 · Read original ↗

ATT&CK techniques detected

4 predictions
T1176Software Extensions
96%
"had accrued as many as 900, 000 unwitting users. a second tactic is to develop and market a legitimate extension, and then insert malicious functionality once the user base has grown large enough. this is the case with the “ urban vpn proxy ” tool spotted by expel. how to minimiz…"
T1176.001Browser Extensions
95%
"experts sound alarm over “ prompt poaching ” browser extensions security experts have warned users to beware of malicious chrome extensions designed to secretly monitor and exfiltrate users ’ ai conversations. expel explained in a blog post, published on march 24, that it had obs…"
T1176.001Browser Extensions
88%
"had accrued as many as 900, 000 unwitting users. a second tactic is to develop and market a legitimate extension, and then insert malicious functionality once the user base has grown large enough. this is the case with the “ urban vpn proxy ” tool spotted by expel. how to minimiz…"
T1176Software Extensions
83%
"experts sound alarm over “ prompt poaching ” browser extensions security experts have warned users to beware of malicious chrome extensions designed to secretly monitor and exfiltrate users ’ ai conversations. expel explained in a blog post, published on march 24, that it had obs…"

Summary

Expel has warned of malicious Chrome extensions stealing users’ AI conversations