{"slug": "ai-hallucinations-trigger-malware-flag-on-1m-active-user-extension", "title": "AI Hallucinations Trigger Malware Flag on 1M+ Active User Extension", "summary": "Magic Actions for YouTube, a Chrome extension with roughly 1 million users and 15+ years of operation, was force-disabled for all users after Chrome flagged its CRX package as containing malware, while Google Search Console and Google Safe Browsing reported a 100% clean status for the same binary. The developer team attributes the enforcement to a single crowdsourced AI vendor, ExodiaLabs, on VirusTotal that flagged the file with a factually false summary about context-menu entries and anonymous telemetry sent to api64.com, a flag the team says was ingested by Safe Browsing telemetry and triggered automated client-side blocking plus a \"Malware Creator\" designation on the account. The team has filed a report on the Chromium Issue Tracker (issue 560237026) and disputed the vendor flag, asking what human-in-the-loop safeguards should be required before AI static analyzers can trigger client-side enforcement.", "body_md": "Hi everyone,\n\nI wanted to share a technical case study regarding a recent false-positive malware enforcement event affecting our extension, Magic Actions for YouTube (~1M users, active for 15+ years).\n\nWe recently uncovered a specific mechanism behind how automated extension flags can trigger a client-side desync between Chrome and Google's backend security status. \n\nI'm sharing this here to start a discussion on how the developer community and Chrome extension team can better handle third-party AI hallucinations.\n\n**1. The Anomaly (Backend vs. Client-Side Desync)**\nSearch Console and Google Safe Browsing reporting \"No issues detected\" (100% clean status) for crx.\n\nChrome at chrome://extensions page suddenly flagged the installed CRX package as \"This extension contains malware\" and force-disabled it for all users.\n\nCRX Hash:\n\n df9a8a4ea4f83d656fd94898011ebb3e75f8be400a439fcbb75c013a02034f22 \n\n(100% identical binary to the CWS build , manually approved! by CWS team.\n\n**2. Root Cause: AI Scanner Hallucination?**\nWhen investigating the CRX binary across security engines, traditional AV vendors (Kaspersky, Defender, Bitdefender, Symantec, etc. 60+engines) returned clean detections.\n\nHowever, a single crowdsourced AI vendor on VirusTotal (ExodiaLabs) flagged the file with a summary:\n\n\"creates context‑menu entries linking to the developer's site, and periodically sends a generated anonymous user ID and usage telemetry to \n\n[https://api64.com](https://api64.com)\n etc.\n\nThis analysis is factually false. The static LLM engine hallucinated benign browser API calls into a dramatic security threat description.\n\n**3. The Negative Feedback Loop**\nBecause Google Safe Browsing ingests crowdsourced threat data from VirusTotal, this single AI hallucination appears to have triggered automated client-side enforcement?\n\n1. AI engine generates hallucinated code summary on VirusTotal.\n\n2. Automated Safe Browsing telemetry ingests the vendor flag.\n\n3. Chrome applies a client-side block on local extensions and CWS put entire account into \"Malware Creator\"! Then anotherextensions automatically Taken Down also!  \n\n4. Users panic at the warning and uninstall the extension, which automated classifiers can misinterpret as user confirmation of a threat.\n\n**Questions for the Community & CWS Team:**\n1. Safe Browsing Telemetry Sync: Has anyone else experienced client-side extension blocks where Search Console reports clean, but Safe Browsing flags the extension in the chrome://extenions ?\n\n2. AI Hallucination Safeguards: As more AI static analyzers join VirusTotal and automated security pipelines, what safeguards or human-in-the-loop verifications should be required before client-side enforcement is triggered?\n\nWe have filed a report on the Chromium Issue Tracker also:\n\n[https://issues.chromium.org/issues/560237026](https://issues.chromium.org/issues/560237026)\nPlus disputed the vendor flag directly, but we would love to hear feedback from other extension developers facing similar AI destructions.\n\nBest regards,\n\nDeveloper Team, Magic Actions for YouTube\n\n[https://www.chromeactions.com](https://www.chromeactions.com)", "url": "https://wpnews.pro/news/ai-hallucinations-trigger-malware-flag-on-1m-active-user-extension", "canonical_source": "https://groups.google.com/a/chromium.org/g/chromium-extensions/c/dG_VSqyli1A", "published_at": "2026-09-12 03:10:17+00:00", "updated_at": "2026-09-12 03:27:30.235202+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-ethics", "ai-tools"], "entities": ["Magic Actions for YouTube", "Google Chrome", "Google Safe Browsing", "VirusTotal", "ExodiaLabs", "Chromium Issue Tracker", "Kaspersky", "Microsoft Defender"], "alternates": {"html": "https://wpnews.pro/news/ai-hallucinations-trigger-malware-flag-on-1m-active-user-extension", "markdown": "https://wpnews.pro/news/ai-hallucinations-trigger-malware-flag-on-1m-active-user-extension.md", "text": "https://wpnews.pro/news/ai-hallucinations-trigger-malware-flag-on-1m-active-user-extension.txt", "jsonld": "https://wpnews.pro/news/ai-hallucinations-trigger-malware-flag-on-1m-active-user-extension.jsonld"}}