BotBeat
...
← Back

> ▌

N/AN/A
INDUSTRY REPORTN/A2026-04-15

WhatRuns Browser Extension Compromised by Malicious Update Exfiltrating URLs and AI Chat Data

Key Takeaways

  • ▸WhatRuns browser extension received a malicious update capable of stealing full URLs and AI chat data from users
  • ▸The compromise represents a supply chain attack affecting a tool with significant user adoption
  • ▸Browser extensions with broad data access permissions present significant security risks when compromised
Source:
Hacker Newshttps://www.youtube.com/watch?v=UYwUmaVohQk↗

Summary

A malicious update to the popular WhatRuns browser extension has been discovered, compromising user security by exfiltrating full URLs and AI chat conversations. The compromised extension, which helps users identify technologies used on websites, was distributed to an unknown number of users through what appears to be a supply chain attack. This incident highlights the vulnerability of widely-used browser extensions and the risks associated with third-party tools that collect browsing data. The extent of the breach and number of affected users remains unclear, though security researchers have documented the malicious behavior through video evidence.

  • Users should review extension permissions and consider removing potentially compromised tools until official patches are released
CybersecurityAI Safety & AlignmentPrivacy & Data

More from N/A

N/AN/A
INDUSTRY REPORT

Investigation: AI-Generated Deepfake Nudes Affecting Nearly 90 Schools Across 28 Countries

2026-04-17
N/AN/A
RESEARCH

Researchers Uncover Mechanisms of Introspective Awareness in Large Language Models

2026-04-16
N/AN/A
RESEARCH

Research Shows AI Assistance May Reduce Persistence and Harm Independent Task Performance

2026-04-16

Comments

Suggested

AnthropicAnthropic
RESEARCH

AI Safety Convergence: Three Major Players Deploy Agent Governance Systems Within Weeks

2026-04-17
OpenAIOpenAI
RESEARCH

When Should AI Step Aside?: Teaching Agents When Humans Want to Intervene

2026-04-17
AnthropicAnthropic
PRODUCT LAUNCH

Finance Leaders Sound Alarm as Anthropic's Claude Mythos Expands to UK Banks

2026-04-17
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us