A group of 18 AI browser extensions marketed as productivity tools are found to be malicious, employing techniques such as remote access Trojans (RATs), man-in-the-middle (MitM) attacks, and infostealers to intercept sensitive user data and browser sessions.