Cyber Security
Critical Security Alert: Dangerous Browser Extensions Targeting Developer Data

Tech News 24×7, 30 December, 2025: In late December 2025, cybersecurity researchers from Socket and CyberInsider uncovered a sophisticated, long-running cyber-espionage operation involving two Google Chrome extensions named “Phantom Shuttle” (幻影穿梭). These extensions, which have been active since 2017, masquerade as legitimate VPN and network speed-testing tools but are designed to steal sensitive user data.
How the Scam Works
- The Facade: The extensions offer a professional interface for developers and trade professionals to test network latency and use a VPN service via a paid subscription (ranging from $1.40 to $13.50 USD).
- The “Smarty” Trap: Once a user pays and logs in, the extension activates a “Smarty” proxy mode. This mode silently routes traffic from over 170 high-value domains—including GitHub, AWS, Twitter, and Facebook—through attacker-controlled servers.
- Data Exfiltration: Using a “Man-in-the-Middle” (MitM) technique, the extension captures plaintext credentials (usernames and passwords), session cookies, and API tokens. It even maintains a “heartbeat” mechanism that sends the user’s data to the attacker’s server every five minutes.
Technical Profile
- Extension IDs:
fbfldogmkadejddihifklefknmikncajandocpcmfmiidofonkbodpdhgddhlcmcofd - Threat Actor Location: Likely based in China (uses Alipay/WeChat Pay and Alibaba Cloud hosting).
- Affected Sites: Over 170 domains (Cloud consoles, social media, and developer platforms).
- Detection Evasion: The malicious code was hidden inside tampered versions of legitimate JavaScript libraries like
jQuery.
Urgent Action Required
If you have either of these extensions installed:
- Remove them immediately via
chrome://extensions. - Clear your browser cookies and cache.
- Change Passwords for any sensitive accounts (Banking, Email, Cloud) accessed while the extension was active.
Official Reference Links
- CyberInsider (Detailed Technical Breakdown): Fake Chrome VPN extensions hijack traffic and steal user credentials
- The Hacker News (Security Advisory): Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites
- Techzine Global (Industry Analysis): Malicious Chrome extensions disguise themselves as proxy services
- Socket Official Research (Source Report): Malicious Chrome Extensions: Phantom Shuttle



