Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
extension-plugin-hijackdata-exfiltration-methodcredential-stealer-activitycommand-and-control-method

Malicious Chrome Extensions Steal ChatGPT and DeepSeek Conversations

Updated 3mo agoFirst seen Jan 7, 20263 sources

Two rogue Chrome extensions, impersonating the legitimate AITOPIA AI sidebar tool, have compromised over 900,000 users by exfiltrating ChatGPT and DeepSeek conversations along with full browsing histories to attacker-controlled servers. The extensions, named "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI" and "AI Sidebar with Deepseek, ChatGPT, Claude and more," request consent for "anonymous analytics" but covertly steal sensitive data, including proprietary code, business strategies, PII, and internal URLs. The malware operates by monitoring browser tabs, scraping chat content and session IDs, and sending Base64-encoded data to C2 servers every 30 minutes, exposing users to risks such as espionage, identity theft, and phishing.

Researchers from OX Security discovered the threat, noting that the extensions remain available on the Chrome Web Store, with one losing its "Featured" badge after disclosure. The extensions also redirect users to each other if uninstalled, and their privacy policies are hosted on third-party sites to obscure their origins. The incident highlights the growing trend of browser extensions being used to capture AI chatbot conversations, a tactic dubbed "Prompt Poaching," and underscores the need for vigilance when installing browser add-ons, especially those requesting broad permissions under the guise of analytics or enhanced user experience.

Share:
Malicious Chrome Extensions Steal ChatGPT and DeepSeek Conversations
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 7, 20266mo ago

Google leaves reported malicious extensions available in Chrome Web Store

Despite being reported to Google, the malicious extensions remained available for download as of 2026-01-07, indicating delayed enforcement in the Chrome Web Store. One of the extensions had its 'Featured' badge removed after disclosure, but both were still accessible to users.

Jan 6, 20266mo ago

Additional scrutiny falls on legitimate extensions collecting AI chat data

By 2026-01-06, reporting also highlighted that legitimate extensions such as Similarweb and Stayfocusd were collecting AI chatbot conversation data, broadening concern beyond outright malicious add-ons. Similarweb was noted as having updated its privacy policy to explicitly reflect this data collection practice.

Dec 29, 20256mo ago

Researchers report nearly 1 million users exposed by extension data theft

Researchers said the two malicious extensions had amassed more than 900,000 installs, exposing users' private AI chats, authentication tokens, internal URLs, proprietary code, business information, and other sensitive data. The findings highlighted risks including corporate espionage, identity theft, phishing, and intellectual property theft.

OX Security uncovers two malicious AI-themed Chrome extensions

On 2025-12-29, OX Security researchers revealed that two Chrome extensions impersonating the legitimate AITOPIA AI sidebar were stealing ChatGPT and DeepSeek conversations along with browsing data from users. The extensions used DOM scraping and browser APIs to collect sensitive chat content, session data, and browsing history, then exfiltrated it to attacker-controlled servers every 30 minutes.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Organizations
8 linked
Ox SecuritySecure AnnexGoogleLovable.devAITOPIALovableSimilarwebSensor Tower
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.