Malicious Chrome Extensions Steal ChatGPT and DeepSeek Conversations
Two rogue Chrome extensions, impersonating the legitimate AITOPIA AI sidebar tool, have compromised over 900,000 users by exfiltrating ChatGPT and DeepSeek conversations along with full browsing histories to attacker-controlled servers. The extensions, named "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI" and "AI Sidebar with Deepseek, ChatGPT, Claude and more," request consent for "anonymous analytics" but covertly steal sensitive data, including proprietary code, business strategies, PII, and internal URLs. The malware operates by monitoring browser tabs, scraping chat content and session IDs, and sending Base64-encoded data to C2 servers every 30 minutes, exposing users to risks such as espionage, identity theft, and phishing.
Researchers from OX Security discovered the threat, noting that the extensions remain available on the Chrome Web Store, with one losing its "Featured" badge after disclosure. The extensions also redirect users to each other if uninstalled, and their privacy policies are hosted on third-party sites to obscure their origins. The incident highlights the growing trend of browser extensions being used to capture AI chatbot conversations, a tactic dubbed "Prompt Poaching," and underscores the need for vigilance when installing browser add-ons, especially those requesting broad permissions under the guise of analytics or enhanced user experience.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Google leaves reported malicious extensions available in Chrome Web Store
Despite being reported to Google, the malicious extensions remained available for download as of 2026-01-07, indicating delayed enforcement in the Chrome Web Store. One of the extensions had its 'Featured' badge removed after disclosure, but both were still accessible to users.
Additional scrutiny falls on legitimate extensions collecting AI chat data
By 2026-01-06, reporting also highlighted that legitimate extensions such as Similarweb and Stayfocusd were collecting AI chatbot conversation data, broadening concern beyond outright malicious add-ons. Similarweb was noted as having updated its privacy policy to explicitly reflect this data collection practice.
Researchers report nearly 1 million users exposed by extension data theft
Researchers said the two malicious extensions had amassed more than 900,000 installs, exposing users' private AI chats, authentication tokens, internal URLs, proprietary code, business information, and other sensitive data. The findings highlighted risks including corporate espionage, identity theft, phishing, and intellectual property theft.
OX Security uncovers two malicious AI-themed Chrome extensions
On 2025-12-29, OX Security researchers revealed that two Chrome extensions impersonating the legitimate AITOPIA AI sidebar were stealing ChatGPT and DeepSeek conversations along with browsing data from users. The extensions used DOM scraping and browser APIs to collect sensitive chat content, session data, and browsing history, then exfiltrated it to attacker-controlled servers every 30 minutes.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
Fake ChatGPT and DeepSeek Extensions Spied on Over 1 Million Chrome Users
hackread.com
Open sourceMalicious Chrome Extension Steal ChatGPT and DeepSeek Conversations from 900K Users
cybersecuritynews.com
Open sourceTwo Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users
thehackernews.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


