Browser Add-Ons, AI Chat Links and In-Memory macOS Attacks: A Week the Internet Worked As Designed

Shady extensions, weaponised Claude conversations, fileless macOS intrusions and cloud agents turned into shells dominated the criminal feeds this week.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Browser Add-Ons, AI Chat Links and In-Memory macOS Attacks: A Week the Internet Worked As Designed
Share

Key points

  • Browser extensions in the Chrome and Edge stores siphoned search traffic and stole clipboard data from retail and corporate victims.
  • Anthropic's Claude shareable conversation links were abused to host lure pages and stage second-step payloads.
  • In-memory macOS loaders targeted iCloud Keychain and crypto wallets, leaving little for forensics teams to recover.
  • NastyC2 npm packages installed a command-and-control beacon via postinstall scripts and lingered as typosquats for days.
  • Device-code phishing harvested Microsoft tokens without a fake portal; conditional access policies that don't restrict the flow are doing the attackers' work.

How bad were the browser extension abuses?

Search traffic got siphoned through add-ons that looked legitimate in the Chrome and Edge stores. The extensions rewrote query results, redirected affiliate clicks and in several cases shipped clipboard-stealing logic alongside the advertised features. Victims ranged from retail consumers to corporate endpoints where the extensions had been sideloaded without security review. We first reported on this delivery method on 15 June, when a 38-account publisher cluster on the Chrome Web Store funnelled new-tab traffic through three ad-fraud backends, and the pattern hasn't slowed.

Were AI platforms actually exploited?

Crooks abused shareable conversation links on Anthropic's Claude to host lure pages and stage second-stage payloads, exploiting the trust users place in a vendor-hosted URL. The link itself is innocuous. What sits on the other side isn't.

How serious are the macOS in-memory attacks?

Responders flagged a fresh wave of intrusions that leave almost no disk artefacts. Initial access came from cracked-app trojans and ClickFix-style social engineering, a delivery chain we traced back to the FlutterShell campaign on 4 June. Once running, loaders pulled stagers directly into memory and targeted iCloud Keychain, browser cookies and crypto wallets. Forensics teams describe the detections as thin and the cleanup as expensive.

Should you worry about cloud agent prompt injection?

Helper bots wired into enterprise SaaS, the kind that read tickets, draft replies and execute API calls, were coaxed into running attacker instructions hidden inside the documents they were told to process. Prompt injection stops being theoretical when the agent has a write-scope token.

What happened with npm this week?

Another supply-chain cluster, tagged NastyC2, appeared in the npm registry. Packages dropped a lightweight command-and-control beacon on install via postinstall scripts. Maintainers pulled the offending versions, but typosquats remained live for days, with developer machines and CI runners as the assumed targets.

Is device-code phishing still a threat?

Operators sent victims a legitimate Microsoft login URL paired with a code the attackers generated, harvesting tokens without standing up a fake portal. Conditional access policies that don't restrict device-code flows are doing the attackers' work for them. Guidance on hardening that flow sits in Microsoft's identity platform docs.

What else moved this week?

Exposed firewalls, VPN concentrators and file-transfer appliances kept showing up in initial-access broker listings. Asking prices tracked the size of the downstream network rather than the bug itself. Cash courier scams aimed at elderly victims, increasingly coordinated through the same Telegram channels that host carding and SIM-swap crews, kept crossing the line between cyber-enabled fraud and physical pickup logistics.

No single incident defined the week. As we noted in our May piece on attackers leaning on trusted tools, the real story is the pattern: stores, chat links, agents and registries keep getting used as carriers. The cost falls on defenders who still treat them as safe by default.

© 2026 Threat Vectr