Malicious Chrome Extensions Caught Stealing AI Conversations from 900,000 Users
Security researchers discovered two Chrome extensions impersonating AI tools that were stealing conversations from ChatGPT and DeepSeek sessions.
Who is affected?
- •Users who installed 'Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI'
- •Users who installed 'AI Sidebar with Deepseek, ChatGPT, Claude and more'
- •Anyone who used these extensions while logged into AI services
Recommended Actions
- Immediately remove the extensions from your browser
- Change passwords for any AI services you used
- Review your conversation history for sensitive information
- Consider rotating any API keys that may have been exposed
What Happened
Security firm OX Security discovered two malicious Chrome extensions that were stealing user conversations from ChatGPT and DeepSeek. Despite containing data-stealing malware, one of the extensions had received Google's "Featured" badge.
The two extensions were:
- "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI" – over 600,000 users
- "AI Sidebar with Deepseek, ChatGPT, Claude and more" – over 300,000 users
The malware exfiltrated complete conversation content to remote C2 servers every 30 minutes, disguised as "anonymous analytics data collection."
Why It Matters
This attack demonstrates how threat actors are increasingly targeting AI users. Your AI conversations may contain:
- Proprietary code
- Business strategies
- Personal information
- API keys and credentials
OX Security warns: "This data can be weaponized for corporate espionage, identity theft, targeted phishing campaigns, or sold on underground forums."
This tactic has been codenamed "Prompt Poaching" by Secure Annex.
Technical Details
The extensions copied the functionality of a legitimate AI sidebar extension (AITOPIA), then added malicious data exfiltration capabilities.
How the attack worked:
- Extensions used
chrome.tabs.onUpdatedAPI for persistent visibility - Silently observed when users navigated to ChatGPT or DeepSeek
- Dynamically extracted content from the webpage's DOM
- Captured full user prompts, AI responses, and session metadata
- Exfiltrated data every 30 minutes to remote servers
Protection Measures
- Only install extensions from verified publishers
- Review extension permissions carefully
- Use browser profiles to isolate sensitive activities
- Consider using AI services in incognito/private mode
- Regularly audit your installed extensions
- The malicious extensions have been removed from the Chrome Web Store
Sources
- •Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats— The Hacker News
- •
- •